CWE-370 - CERT CVE

CWE-370 - Missing Check for Certificate Revocation after Initial Check

The software does not check the revocation status of a certificate after its initial revocation check, which can cause the software to perform privileged actions even after the certificate is revoked at a later time.

CAPEC ID Naziv
CAPEC-26 Leveraging Race Conditions
CAPEC-29 Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions