CVE-2010-4211

PayPal < 3.0 - Improper Certificate Validation

Title source: llm
STIX 2.1

Description

The PayPal app before 3.0.1 for iOS does not verify that the server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof a PayPal web server via an arbitrary certificate.

References (8)

Core 8
Core References
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/2887
Various Sources x_refsource_misc
http://news.cnet.com/8301-27080_3-20021730-245.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/44657
Various Sources x_refsource_misc
http://itunes.apple.com/us/app/paypal/id283646709
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/63002

Scores

EPSS 0.0037
EPSS Percentile 29.0%

Details

CWE
CWE-287
Status published
Products (1)
ebay/paypal < 3.0
Published Nov 09, 2010
Tracked Since Feb 18, 2026