Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-1000097

Опубликовано: 01 дек. 2016
Источник: redhat
CVSS3: 4.3
CVSS2: 2.6
EPSS Низкий

Описание

On Darwin, user's trust preferences for root certificates were not honored. If the user had a root certificate loaded in their Keychain that was explicitly not trusted, a Go program would still verify a connection using that root certificate.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7golangWill not fix
Red Hat OpenShift Enterprise 3golangAffected
Red Hat OpenStack Platform 10 (Newton) Operational ToolsgolangNot affected
Red Hat OpenStack Platform 8 (Liberty) Operational ToolsgolangWill not fix
Red Hat OpenStack Platform 9 (Mitaka) Operational ToolsgolangWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-295
https://bugzilla.redhat.com/show_bug.cgi?id=1404636golang: User's trust preferences for root certificates were not honored

EPSS

Процентиль: 67%
0.01287
Низкий

4.3 Medium

CVSS3

2.6 Low

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 9 лет назад

On Darwin, user's trust preferences for root certificates were not honored. If the user had a root certificate loaded in their Keychain that was explicitly not trusted, a Go program would still verify a connection using that root certificate.

CVSS3: 7.5
nvd
почти 9 лет назад

On Darwin, user's trust preferences for root certificates were not honored. If the user had a root certificate loaded in their Keychain that was explicitly not trusted, a Go program would still verify a connection using that root certificate.

msrc
5 месяцев назад

On Darwin, user's trust preferences for root certificates were not honored. If the user had a root certificate loaded in their Keychain that was explicitly not trusted, a Go program would still verify a connection using that root certificate.

CVSS3: 7.5
debian
почти 9 лет назад

On Darwin, user's trust preferences for root certificates were not hon ...

CVSS3: 7.5
github
около 4 лет назад

On Darwin, user's trust preferences for root certificates were not honored. If the user had a root certificate loaded in their Keychain that was explicitly not trusted, a Go program would still verify a connection using that root certificate.

EPSS

Процентиль: 67%
0.01287
Низкий

4.3 Medium

CVSS3

2.6 Low

CVSS2