In Botan before 2.19.3, it is possible to forge OCSP responses due to a certificate verification error. This issue was introduced in Botan 1.11.34 (November 2016).
CVSS Details
- CVSS 3.1 Base Score: 9.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade botan | Mar 21, 2024 | Nov 27, 2022 |
| Debian | — | Upgrade botan | Jul 30, 2024 | Nov 27, 2022 |
| Suse | — | Upgrade libbotan-2-18-64bitUpgrade libbotan-2-18Upgrade libbotan-2-10Upgrade libbotan-devel-32bitUpgrade libbotan-develUpgrade libbotan-2-10-64bitUpgrade libbotan-devel-64bitUpgrade botanUpgrade libbotan-2-18-32bitUpgrade botan-docUpgrade libbotan-2-10-32bitUpgrade python3-botan | Nov 24, 2022 | Nov 23, 2022 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Nov 27, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub