Nginx Improper Certificate Validation Vulnerability - CVE-2021-3618 - Vulnerability Database

Nginx Improper Certificate Validation Vulnerability - CVE-2021-3618

High
Reference: CVE-2021-3618
Title: Nginx Improper Certificate Validation Vulnerability
Overview:

ALPACA is an application layer protocol content confusion attack exploiting TLS servers implementing different protocols but using compatible certificates such as multi-domain or wildcard certificates. A MiTM attacker having access to victim39s traffic at the TCP/IP layer can redirect traffic from one subdomain to another resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.