Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-1000097

Опубликовано: 01 дек. 2016
Источник: redhat
CVSS3: 4.3
CVSS2: 2.6
EPSS Низкий

Описание

On Darwin, user's trust preferences for root certificates were not honored. If the user had a root certificate loaded in their Keychain that was explicitly not trusted, a Go program would still verify a connection using that root certificate.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7golangWill not fix
Red Hat OpenShift Enterprise 3golangAffected
Red Hat OpenStack Platform 10 (Newton) Operational ToolsgolangNot affected
Red Hat OpenStack Platform 8 (Liberty) Operational ToolsgolangWill not fix
Red Hat OpenStack Platform 9 (Mitaka) Operational ToolsgolangWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-295
https://bugzilla.redhat.com/show_bug.cgi?id=1404636golang: User's trust preferences for root certificates were not honored

EPSS

Процентиль: 39%
0.00177
Низкий

4.3 Medium

CVSS3

2.6 Low

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

On Darwin, user's trust preferences for root certificates were not honored. If the user had a root certificate loaded in their Keychain that was explicitly not trusted, a Go program would still verify a connection using that root certificate.

CVSS3: 7.5
nvd
больше 8 лет назад

On Darwin, user's trust preferences for root certificates were not honored. If the user had a root certificate loaded in their Keychain that was explicitly not trusted, a Go program would still verify a connection using that root certificate.

msrc
5 месяцев назад

On Darwin, user's trust preferences for root certificates were not honored. If the user had a root certificate loaded in their Keychain that was explicitly not trusted, a Go program would still verify a connection using that root certificate.

CVSS3: 7.5
debian
больше 8 лет назад

On Darwin, user's trust preferences for root certificates were not hon ...

CVSS3: 7.5
github
больше 3 лет назад

On Darwin, user's trust preferences for root certificates were not honored. If the user had a root certificate loaded in their Keychain that was explicitly not trusted, a Go program would still verify a connection using that root certificate.

EPSS

Процентиль: 39%
0.00177
Низкий

4.3 Medium

CVSS3

2.6 Low

CVSS2