The TLS engine in Kwik commit 745fd4e2 does not track the current state of the connection. This vulnerability can allow Client Hello messages to be overwritten at any time, including after a connection has been established.
Metrics
Affected Vendors & Products
References
History
Thu, 22 Aug 2024 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-372 | |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-22T20:02:04.663Z
Reserved:
Link: CVE-2024-22590
Vulnrichment
Updated: 2024-08-01T22:51:11.067Z
NVD
Status : Awaiting Analysis
Published: 2024-05-28T16:15:12.573
Modified: 2024-08-22T20:35:03.440
Link: CVE-2024-22590
Redhat
No data.