MEDIUM
WeeChat (aka Wee Enhanced Environment for Chat) 3.2 to 3.4 before 3.4.1 does not properly verify the TLS certificate of the server, after certain GnuTLS options are changed, which allows man-in-the-middle attackers to spoof a TLS chat server via an arbitrary certificate
Published Apr 2, 2022
4.8
MEDIUMCVSS 3.1
EPSS 0.43%
Description
Affected products
Remediation
References (3)
Change history (0)
No recorded changes yet.