wolfSSL before 4.8.1 incorrectly skips OCSP verification in certain situations of irrelevant response data that contains the NoCheck extension.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-38597.json"
[
{
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/wolfssl/wolfssl/commit/723ed009ae5dc68acc14cd7664f93503d64cd51d",
"digest": {
"line_hashes": [
"129559050910902772593620305703892358584",
"46892446780360592572869157630891092452",
"208066940593629570183817566574157000651",
"11078029748587033735632828975921038305",
"81904379545604931314036370645668216769",
"661704961450447980007833454441287648"
],
"threshold": 0.9
},
"id": "CVE-2021-38597-1072c300",
"deprecated": false,
"target": {
"file": "wolfcrypt/src/port/caam/caam_qnx.c"
}
}
]