Description
OWASP Zed Attack Proxy (ZAP) through w2022-03-21 does not verify the TLS certificate chain of an HTTPS server.
Remediation
References
https://github.com/zaproxy/zaproxy/issues/7165
http://www.openwall.com/lists/oss-security/2022/03/24/3
https://github.com/zaproxy/zaproxy/releases
https://www.openwall.com/lists/oss-security/2022/03/23/1
Related Vulnerabilities
CVE-2021-29481 Vulnerability in maven package io.ratpack:ratpack-session
CVE-2023-34455 Vulnerability in maven package org.xerial.snappy:snappy-java
CVE-2023-24163 Vulnerability in maven package cn.hutool:hutool-all
CVE-2016-10551 Vulnerability in npm package waterline-sequel
CVE-2021-26539 Vulnerability in maven package org.webjars.npm:sanitize-html