CVE-2023-0465

Invalid certificate policies in leaf certificates are silently ignored

Applications that use a non-default option when verifying certificates may be vulnerable to an attack from a malicious CA to circumvent certain checks. Invalid certificate policies in leaf certificates are silently ignored by OpenSSL and other certificate policy checks are skipped for that certificate. A malicious CA could use this to deliberately assert invalid certificate policies in order to circumvent policy checking on the certificate altogether. Policy processing is disabled by default but can be enabled by passing the `-policy' argument to the command line utilities or by calling the `X509_VERIFY_PARAM_set1_policies()' function.


We have discovered 26,461 live websites that are affected by CVE-2023-0465.

Test my site




Affected Software

Product  OpenSSL
Category Web Server Extensions
Vulnerable Domains26,461 live websites (3.95% of OpenSSL install base)
Vulnerable Versions
  • from 3 before 3.0.9
  • from 3.1 before 3.1.1
Vulnerable Versions Count9 versions ( 22.50% of all versions)



Details

  • Published - Mar 28, 2023
  • Updated - Feb 18, 2025

Credits

  • David Benjamin (Google) (reporter)
  • Matt Caswell (remediation developer)

CVE-2023-0465 usage by Country

United States12,695 websites



France2,385 websites
Germany1,547 websites
Japan1,443 websites
GB891 websites
Canada880 websites
Finland691 websites
Netherlands637 websites
Italy442 websites
Hungary406 websites

CVE-2023-0465 usage by TLD

.com11,579 websites
.org1,244 websites
.net1,159 websites
.jp939 websites
.edu829 websites
.ca741 websites
.co.uk720 websites
.nl558 websites
.fi550 websites
.fr545 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-0465

Top websites that are affected by CVE-2023-0465. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.com United States*,***
***.***********.com United States*,***
*******.com United States*,***
******.***************.com United States*,***
****************.com United States**,***
**.***.au Australia**,***
***.edu United States**,***
*********.ch United States**,***
******.org Singapore**,***
********.org France**,***
See full domain list

FAQ

A total of 26,461 websites have been identified as vulnerable to CVE-2023-0465, discovered through global website indexing conducted by WebTechSurvey.
OpenSSL is susceptible to CVE-2023-0465 vulnerability.
OpenSSL versions before 3.1.1 are vulnerable to CVE-2023-0465.
Version 3.1.1 of OpenSSL addresses the CVE-2023-0465 security vulnerability.