CWE-298Variant

Improper Validation of Certificate Expiration

Draft in the CWE catalog · 6 CVEs mapped

6
CVEs mapped
5.8
Median CVSS
What it is

A certificate expiration is not validated or is incorrectly validated.

Recent examples
3.7cvss
CVE-2026-86231

mwiede jsch KnownHosts.java getRevokedKeys improper check for certificate revocation

A security flaw has been discovered in mwiede jsch up to 2.28.5. Affected is the function getRevokedKeys of the file src/main/java/com/jcraft/jsch/KnownHosts.java. Performing a manipulation of the argument known_hosts results in improper check for certificate revocation. The attack is possible to be carried out remotely. The attack is considered to have high complexity. The exploitability is told to be difficult. The exploit has been released to the public and may be used for attacks. Upgrading to version 2.28.6 is able to address this issue. The patch is named 194a2f76a5c0f1c3f778565be3fd66bcafc42d23. You should upgrade the affected component.

LOWno explanation yet
epss
4.8cvss
CVE-2024-1248

Role Overwriting via Silent JIT Provisioning in Multiple WSO2 Products Enables Privilege Escalation

The silent Just-In-Time (JIT) provisioning feature in federated authentication implementations fails to properly segregate user roles during account creation when a federated user shares a username with a local user. This allows the provisioning process to overwrite existing roles of local users with roles assigned to the federated user. Exploitation requires a federated identity provider (IDP) with silent JIT provisioning enabled and an attacker's knowledge of a local user's username. When these conditions are met, a malicious individual can leverage the JIT provisioning process to modify the roles of local users. The overwritten roles are limited to those defined within the federated IDP, typically granting minimal access rights unless explicitly configured otherwise by the federated IDP administrator.

MEDIUMno explanation yet
0%
epss
7.1cvss
CVE-2025-61736

iSTAR- Improper Validation of Certificate Expiration

Successful exploitation of this vulnerability could result in the product failing to re-establish communication once the certificate expires.

HIGHno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-298
Abstraction
Variant
Structure
Simple
Status
Draft
References (1)