Loading...
Loading...
A certain Apple patch for OpenSSL in Apple OS X 10.9.2 and earlier uses a Trust Evaluation Agent (TEA) feature without terminating certain TLS/SSL handshakes as specified in the SSL_CTX_set_verify callback function's documentation, which allows remote attackers to bypass extra verification within a custom application via a crafted certificate chain that is acceptable to TEA but not acceptable to that application.
March 5, 2014
April 29, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2014-2234
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.