OWASP Zed Attack Proxy (ZAP) through w2022-03-21 does not verify the TLS certificate chain of an HTTPS server.
{ "cwe_ids": [ "CWE-295" ], "severity": "MODERATE", "github_reviewed_at": "2022-04-01T20:09:29Z", "github_reviewed": true, "nvd_published_at": "2022-03-24T04:15:00Z" }