{"id":"CVE-2018-21029","details":"systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS. Server Name Indication (SNI) is not sent, and there is no hostname validation with the GnuTLS backend. NOTE: This has been disputed by the developer as not a vulnerability since hostname validation does not have anything to do with this issue (i.e. there is no hostname to be sent)","modified":"2026-08-07T11:48:02.635534050Z","published":"2019-10-30T22:15:10.667Z","related":["openSUSE-SU-2024:11420-1"],"database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"31"},{"last_affected":"31"}],"source":"CPE_STRING","vendor_product":"fedoraproject:fedora"}]},"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4NLJVOJMB6ANDILRLDZK26YGLYBEPHKY/"},{"type":"ADVISORY","url":"https://blog.cloudflare.com/dns-encryption-explained/"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20191122-0002/"},{"type":"ADVISORY","url":"https://tools.ietf.org/html/rfc7858#section-4.1"},{"type":"REPORT","url":"https://github.com/systemd/systemd/issues/9397"},{"type":"FIX","url":"https://github.com/systemd/systemd/blob/v243/src/resolve/resolved-dnstls-gnutls.c#L62-L63"},{"type":"FIX","url":"https://github.com/systemd/systemd/pull/13870"},{"type":"EVIDENCE","url":"https://github.com/systemd/systemd/blob/v239/man/resolved.conf.xml#L199-L207"},{"type":"EVIDENCE","url":"https://github.com/systemd/systemd/blob/v243/man/resolved.conf.xml#L196-L207"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/systemd/systemd","events":[{"introduced":"de7436b02badc82200dc127ff190b8155769b8e7"},{"fixed":"db9c5ae73e23d816e2df2a3e10a9a2a60b5b3ed7"}],"database_specific":{"extracted_events":[{"introduced":"239"},{"fixed":"244"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:systemd_project:systemd:*:*:*:*:*:*:*:*"}}],"versions":["v244-rc1","v243","v243-rc2","v243-rc1","v242","v242-rc4","v242-rc3","v242-rc2","v242-rc1","v241","v241-rc2","v241-rc1","v240","v239"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-21029.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/systemd/systemd-stable","events":[{"introduced":"de7436b02badc82200dc127ff190b8155769b8e7"},{"fixed":"db9c5ae73e23d816e2df2a3e10a9a2a60b5b3ed7"}],"database_specific":{"cpe":"cpe:2.3:a:systemd_project:systemd:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"239"},{"fixed":"244"}],"source":"CPE_RANGE"}}],"versions":["v244-rc1","v243","v243-rc2","v243-rc1","v242","v242-rc4","v242-rc3","v242-rc2","v242-rc1","v241","v241-rc2","v241-rc1","v240","v239"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-21029.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}