Description
Invicti detected a hostname mismatch in the SSL certificate. This happens when the common name to which an SSL Certificate is issued (e.g., www.example.com) doesn't exactly match the name displayed in the URL bar.
Remediation
The process of fixing name-hostname mismatch issues varies depending on the host or the certificate authority used. Please refer to the corresponding documentation.
References
Related Vulnerabilities
MongoDb Improper Certificate Validation Vulnerability (CVE-2023-1409)
Django Improper Certificate Validation Vulnerability (CVE-2020-13254)
LimeSurvey Improper Certificate Validation Vulnerability (CVE-2019-16179)
Envoy Proxy Improper Certificate Validation Vulnerability (CVE-2022-21657)
Jenkins Improper Certificate Validation Vulnerability (CVE-2017-1000396)