Vulnerability Description
In Erlang/OTP before 23.3.4.15, 24.x before 24.3.4.2, and 25.x before 25.0.2, there is a Client Authentication Bypass in certain client-certification situations for SSL, TLS, and DTLS.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Erlang | Erlang\/Otp | < 23.3.4.15 |
References
- https://erlangforums.com/c/erlang-news-announcements/91Release NotesVendor Advisory
- https://erlangforums.com/t/otp-25-1-released/1854Release NotesVendor Advisory
- https://github.com/erlang/otp/compare/OTP-23.3.4.14...OTP-23.3.4.15PatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/07/msg00012.html
- https://erlangforums.com/c/erlang-news-announcements/91Release NotesVendor Advisory
- https://erlangforums.com/t/otp-25-1-released/1854Release NotesVendor Advisory
- https://github.com/erlang/otp/compare/OTP-23.3.4.14...OTP-23.3.4.15PatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/07/msg00012.html
FAQ
What is CVE-2022-37026?
CVE-2022-37026 is a vulnerability with a CVSS score of 9.8 (CRITICAL). In Erlang/OTP before 23.3.4.15, 24.x before 24.3.4.2, and 25.x before 25.0.2, there is a Client Authentication Bypass in certain client-certification situations for SSL, TLS, and DTLS.
How severe is CVE-2022-37026?
CVE-2022-37026 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-37026?
Check the references section above for vendor advisories and patch information. Affected products include: Erlang Erlang\/Otp.