Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v8jf-78w9-hp93

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

In Go before 1.13.13 and 1.14.x before 1.14.5, Certificate.Verify may lack a check on the VerifyOptions.KeyUsages EKU requirements (if VerifyOptions.Roots equals nil and the installation is on Windows). Thus, X.509 certificate verification is incomplete.

In Go before 1.13.13 and 1.14.x before 1.14.5, Certificate.Verify may lack a check on the VerifyOptions.KeyUsages EKU requirements (if VerifyOptions.Roots equals nil and the installation is on Windows). Thus, X.509 certificate verification is incomplete.

EPSS

Процентиль: 61%
0.0041
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 5 лет назад

In Go before 1.13.13 and 1.14.x before 1.14.5, Certificate.Verify may lack a check on the VerifyOptions.KeyUsages EKU requirements (if VerifyOptions.Roots equals nil and the installation is on Windows). Thus, X.509 certificate verification is incomplete.

CVSS3: 5.3
nvd
больше 5 лет назад

In Go before 1.13.13 and 1.14.x before 1.14.5, Certificate.Verify may lack a check on the VerifyOptions.KeyUsages EKU requirements (if VerifyOptions.Roots equals nil and the installation is on Windows). Thus, X.509 certificate verification is incomplete.

CVSS3: 5.3
msrc
больше 5 лет назад

Описание отсутствует

CVSS3: 5.3
debian
больше 5 лет назад

In Go before 1.13.13 and 1.14.x before 1.14.5, Certificate.Verify may ...

suse-cvrf
около 5 лет назад

Security update for terraform

EPSS

Процентиль: 61%
0.0041
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-295