The product does not follow, or incorrectly follows, the chain of trust for a certificate back to a trusted root certificate, resulting in incorrect trust of any resource that is associated with that certificate.
Ensure that proper certificate checking is included in the system design.
Understand, and properly implement all checks necessary to ensure the integrity of certificate trust integrity.
If certificate pinning is being used, ensure that all relevant properties of the certificate are fully validated before the certificate is pinned, including the full chain of trust.
Our security experts can help you identify and remediate CWE-296 vulnerabilities in your codebase.
Get Security Assessment