CVE-2020-13615

Source
https://cve.org/CVERecord?id=CVE-2020-13615
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-13615.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-13615
Downstream
Related
Published
2020-05-26T23:15:10Z
Modified
2026-08-27T08:40:50Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

lib/QoreSocket.cpp in Qore before 0.9.4.2 lacks hostname verification for X.509 certificates.

References

Affected packages

Git / github.com/qoretechnologies/qore

Affected ranges

Type
GIT
Repo
https://github.com/qoretechnologies/qore
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "cpe": "cpe:2.3:a:qore:qore:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "0.9.4.2"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

release-0.*
release-0.9.0
release-0.9.1
release-0.9.2
release-0.9.3
release-0.9.4
release-0.9.4.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-13615.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "function_hash": "10118540587415872638697988763624137769",
            "length": 2307
        },
        "id": "CVE-2020-13615-3539be9e",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/qoretechnologies/qore/commit/800dbd241498f4edf889d1c3505c98f894e212d4",
        "target": {
            "file": "lib/Function.cpp",
            "function": "QoreFunction::parseCheckDuplicateSignature"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "277365115843210278806388379532013813466",
                "136239684937609925673638639642386246008",
                "274570330623160609558701460446970783818",
                "21688478443636684128565720958369173346",
                "158090598638927839675445350894498360480",
                "186681148535507041529847502869273429236",
                "92892435614497211984595590445582206667",
                "79084743693411868078639941045840948236",
                "167756866541223465695613586627332802290",
                "158090598638927839675445350894498360480",
                "5702662798046728584313952421750973160",
                "310714214476407036424987355877950181601",
                "308962744438064076613458528629664915222",
                "184145553116271377348077451428008354716",
                "206472000269013669021504943907726609127",
                "324704775928432071540876152353336782320",
                "158090598638927839675445350894498360480",
                "70150976955079193657134207077959304139",
                "124585172961334532597379493373741518204",
                "103441582241830520666426468873238615109",
                "71351036080384084311336757789282057731",
                "158090598638927839675445350894498360480",
                "75407180318704451699303769443305508093",
                "108587633537507210242609878158511307392",
                "248700297221394034611502018879561245327",
                "301135177604534480532991135870401081661",
                "93793826385461512460887587207539687316",
                "277513556761597835139858003934159597950",
                "158090598638927839675445350894498360480",
                "186681148535507041529847502869273429236",
                "92892435614497211984595590445582206667",
                "79084743693411868078639941045840948236",
                "167756866541223465695613586627332802290"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2020-13615-c2632de6",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/qoretechnologies/qore/commit/800dbd241498f4edf889d1c3505c98f894e212d4",
        "target": {
            "file": "lib/Function.cpp"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "91544065061414831649525290642275236835",
                "203609391946035949777510548702818068425",
                "206149495641689139819116549765547488190",
                "51508924493713431599327464793115054603",
                "132581377537088840571477312181822866948",
                "295450169771410729633492190967398122100",
                "279880304327084632485904000390757689206",
                "182361314576428306933531983957363829767",
                "274209628453703359430697749853098756118",
                "333823696877182278208997672342684001781",
                "6777263511514130063355710674801912358",
                "288779117219276555280647328405674443922",
                "282757376555700414868251410829239477215",
                "89501487353769323572412526842170292112",
                "191291866937921623392732508004048993041"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2020-13615-e6d031b6",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/qoretechnologies/qore/commit/800dbd241498f4edf889d1c3505c98f894e212d4",
        "target": {
            "file": "include/qore/intern/QoreTypeInfo.h"
        }
    }
]
vanir_signatures_modified
"2026-08-27T08:40:50Z"