Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v8jf-78w9-hp93

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

In Go before 1.13.13 and 1.14.x before 1.14.5, Certificate.Verify may lack a check on the VerifyOptions.KeyUsages EKU requirements (if VerifyOptions.Roots equals nil and the installation is on Windows). Thus, X.509 certificate verification is incomplete.

In Go before 1.13.13 and 1.14.x before 1.14.5, Certificate.Verify may lack a check on the VerifyOptions.KeyUsages EKU requirements (if VerifyOptions.Roots equals nil and the installation is on Windows). Thus, X.509 certificate verification is incomplete.

EPSS

Процентиль: 76%
0.01762
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 6 лет назад

In Go before 1.13.13 and 1.14.x before 1.14.5, Certificate.Verify may lack a check on the VerifyOptions.KeyUsages EKU requirements (if VerifyOptions.Roots equals nil and the installation is on Windows). Thus, X.509 certificate verification is incomplete.

CVSS3: 5.3
nvd
около 6 лет назад

In Go before 1.13.13 and 1.14.x before 1.14.5, Certificate.Verify may lack a check on the VerifyOptions.KeyUsages EKU requirements (if VerifyOptions.Roots equals nil and the installation is on Windows). Thus, X.509 certificate verification is incomplete.

CVSS3: 5.3
msrc
почти 6 лет назад

Описание отсутствует

CVSS3: 5.3
debian
около 6 лет назад

In Go before 1.13.13 and 1.14.x before 1.14.5, Certificate.Verify may ...

suse-cvrf
больше 5 лет назад

Security update for terraform

EPSS

Процентиль: 76%
0.01762
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-295