Description
OWASP Zed Attack Proxy (ZAP) through w2022-03-21 does not verify the TLS certificate chain of an HTTPS server.
Remediation
References
https://github.com/zaproxy/zaproxy/issues/7165
http://www.openwall.com/lists/oss-security/2022/03/24/3
https://github.com/zaproxy/zaproxy/releases
https://www.openwall.com/lists/oss-security/2022/03/23/1
Related Vulnerabilities
CVE-2013-4221 Vulnerability in maven package org.restlet:org.restlet
CVE-2023-22457 Vulnerability in maven package org.xwiki.contrib:application-ckeditor-plugins
CVE-2021-21391 Vulnerability in npm package @ckeditor/ckeditor5-list
CVE-2023-27087 Vulnerability in maven package com.xuxueli:xxl-job
CVE-2018-1000118 Vulnerability in maven package org.webjars.npm:electron