Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-24783

Опубликовано: 05 мар. 2024
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

Verifying a certificate chain which contains a certificate with an unknown public key algorithm will cause Certificate.Verify to panic. This affects all crypto/tls clients, and servers that set Config.ClientAuth to VerifyClientCertIfGiven or RequireAndVerifyClientCert. The default behavior is for TLS servers to not verify client certificates.

A flaw was found in Go's crypto/x509 standard library package. Verifying a certificate chain that contains a certificate with an unknown public key algorithm will cause a Certificate.Verify to panic. This issue affects all crypto/tls clients and servers that set Config.ClientAuth to VerifyClientCertIfGiven or RequireAndVerifyClientCert.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
cert-manager Operator for Red Hat OpenShiftcert-manager-operator-containerNot affected
Cost Management Metrics Operatorcostmanagement-metrics-operator-containerAffected
Fence Agents Remediation Operatorworkload-availability/fence-agents-remediation-rhel8-operatorWill not fix
Machine Deletion Remediation Operatorworkload-availability/machine-deletion-remediation-rhel8-operatorAffected
Migration Toolkit for Applications 6mta/mta-hub-rhel8Will not fix
Migration Toolkit for Applications 7mta/mta-cli-rhel9Not affected
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-api-rhel9Affected
mirror registry for Red Hat OpenShiftmirror-registry-containerAffected
Multicluster Engine for Kubernetesmulticluster-engine-hive-containerWill not fix
NBDE Tang Servertang-operator-containerWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-295
https://bugzilla.redhat.com/show_bug.cgi?id=2268019golang: crypto/x509: Verify panics on certificates with an unknown public key algorithm

EPSS

Процентиль: 49%
0.00667
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 2 лет назад

Verifying a certificate chain which contains a certificate with an unknown public key algorithm will cause Certificate.Verify to panic. This affects all crypto/tls clients, and servers that set Config.ClientAuth to VerifyClientCertIfGiven or RequireAndVerifyClientCert. The default behavior is for TLS servers to not verify client certificates.

CVSS3: 5.9
nvd
больше 2 лет назад

Verifying a certificate chain which contains a certificate with an unknown public key algorithm will cause Certificate.Verify to panic. This affects all crypto/tls clients, and servers that set Config.ClientAuth to VerifyClientCertIfGiven or RequireAndVerifyClientCert. The default behavior is for TLS servers to not verify client certificates.

CVSS3: 5.9
msrc
11 месяцев назад

Verify panics on certificates with an unknown public key algorithm in crypto/x509

CVSS3: 5.9
debian
больше 2 лет назад

Verifying a certificate chain which contains a certificate with an unk ...

CVSS3: 5.9
github
больше 2 лет назад

Verifying a certificate chain which contains a certificate with an unknown public key algorithm will cause Certificate.Verify to panic. This affects all crypto/tls clients, and servers that set Config.ClientAuth to VerifyClientCertIfGiven or RequireAndVerifyClientCert. The default behavior is for TLS servers to not verify client certificates.

EPSS

Процентиль: 49%
0.00667
Низкий

5.9 Medium

CVSS3