CVE-2020-13645: Broadcom Fabric Operating System
Medium severity, CVSS 6.5. EPSS: 2% chance of exploitation in the next 30 days.
In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if the application fails to specify the expected server identity. This is in contrast to its intended documented behavior, to fail the certificate verification. Applications that fail to provide the server identity, including Balsa before 2.5.11 and 2.6.x before 2.6.1, accept a TLS certificate if the certificate is valid for any host.
Affected products
- Broadcom Fabric Operating System: affected versions not specified
- Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 19.10 only; version 20.04 only
- Fedoraproject Fedora: version 31 only; version 32 only
- Gnome Balsa: before 2.5.11 (fixed in 2.5.11); version 2.6.0 only
- Gnome Glib-Networking: before 2.62.4 (fixed in 2.62.4); from 2.64.0, before 2.64.3 (fixed in 2.64.3)
- Netapp Cloud Backup: affected versions not specified
Published 2020-05-28. Last modified 2026-06-17.