ARM mbed TLS before 1.3.21 and 2.x before 2.1.9, if optional authentication is configured, allows remote attackers to bypass peer authentication via an X.509 certificate chain with many intermediates. NOTE: although mbed TLS was formerly known as PolarSSL, the releases shipped with the PolarSSL name are not affected.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "1.3.10"
},
{
"introduced": "0"
},
{
"last_affected": "1.3.11"
},
{
"introduced": "0"
},
{
"last_affected": "1.3.12"
},
{
"introduced": "0"
},
{
"last_affected": "1.3.13"
},
{
"introduced": "0"
},
{
"last_affected": "1.3.14"
},
{
"introduced": "0"
},
{
"last_affected": "1.3.15"
},
{
"introduced": "0"
},
{
"last_affected": "1.3.16"
},
{
"introduced": "0"
},
{
"last_affected": "1.3.17"
},
{
"introduced": "0"
},
{
"last_affected": "1.3.18"
},
{
"introduced": "0"
},
{
"last_affected": "1.3.19"
},
{
"introduced": "0"
},
{
"last_affected": "1.3.20"
},
{
"introduced": "0"
},
{
"last_affected": "1.3.21"
},
{
"introduced": "0"
},
{
"last_affected": "2.0.0"
},
{
"introduced": "0"
},
{
"last_affected": "2.1.0"
},
{
"introduced": "0"
},
{
"last_affected": "2.1.1"
},
{
"introduced": "0"
},
{
"last_affected": "2.1.2"
},
{
"introduced": "0"
},
{
"last_affected": "2.1.3"
},
{
"introduced": "0"
},
{
"last_affected": "2.1.4"
},
{
"introduced": "0"
},
{
"last_affected": "2.1.5"
},
{
"introduced": "0"
},
{
"last_affected": "2.1.6"
},
{
"introduced": "0"
},
{
"last_affected": "2.1.7"
},
{
"introduced": "0"
},
{
"last_affected": "2.1.8"
},
{
"introduced": "0"
},
{
"last_affected": "2.1.9"
},
{
"introduced": "0"
},
{
"last_affected": "2.2.0"
},
{
"introduced": "0"
},
{
"last_affected": "2.2.1"
},
{
"introduced": "0"
},
{
"last_affected": "2.3.0"
},
{
"introduced": "0"
},
{
"last_affected": "2.4.0"
},
{
"introduced": "0"
},
{
"last_affected": "2.4.2"
},
{
"introduced": "0"
},
{
"last_affected": "2.5.1"
}
]
}