Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-45341

Опубликовано: 17 янв. 2025
Источник: redhat
CVSS3: 4.2
EPSS Низкий

Описание

A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that applies to the certificate chain. Certificates containing URIs are not permitted in the web PKI, so this only affects users of private PKIs which make use of URIs.

A flaw was found in the crypto/x509 package of the Golang standard library. A certificate with a URI, which has a IPv6 address with a zone ID, may incorrectly satisfy a URI name constraint that applies to the certificate chain. Certificates containing URIs are not permitted in the web PKI; this issue only affects users of private PKIs that make use of URIs.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Assisted Installer for Red Hat OpenShift Container Platform 2rhai-tech-preview/assisted-installer-agent-rhel8Fix deferred
Assisted Installer for Red Hat OpenShift Container Platform 2rhai-tech-preview/assisted-installer-rhel8Fix deferred
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-rhel9-operatorFix deferred
cert-manager Operator for Red Hat OpenShiftcert-manager/cert-manager-operator-rhel9Fix deferred
cert-manager Operator for Red Hat OpenShiftcert-manager/jetstack-cert-manager-rhel9Fix deferred
Cryostat 3cryostat-tech-preview/cryostat-ose-oauth-proxy-rhel8Fix deferred
Cryostat 3cryostat-tech-preview/cryostat-rhel8-operatorFix deferred
Cryostat 3cryostat-tech-preview/cryostat-storage-rhel8Fix deferred
Custom Metric Autoscaler operator for Red Hat Openshiftcustom-metrics-autoscaler/custom-metrics-autoscaler-rhel8Fix deferred
Custom Metric Autoscaler operator for Red Hat Openshiftcustom-metrics-autoscaler-tech-preview/custom-metrics-autoscaler-rhel8-operatorFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-347
https://bugzilla.redhat.com/show_bug.cgi?id=2341750golang: crypto/x509: crypto/x509: usage of IPv6 zone IDs can bypass URI name constraints

EPSS

Процентиль: 3%
0.00017
Низкий

4.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
5 месяцев назад

A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that applies to the certificate chain. Certificates containing URIs are not permitted in the web PKI, so this only affects users of private PKIs which make use of URIs.

CVSS3: 6.1
nvd
5 месяцев назад

A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that applies to the certificate chain. Certificates containing URIs are not permitted in the web PKI, so this only affects users of private PKIs which make use of URIs.

CVSS3: 6.1
msrc
4 месяца назад

Описание отсутствует

CVSS3: 6.1
debian
5 месяцев назад

A certificate with a URI which has a IPv6 address with a zone ID may i ...

CVSS3: 6.1
github
5 месяцев назад

A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that applies to the certificate chain. Certificates containing URIs are not permitted in the web PKI, so this only affects users of private PKIs which make use of URIs.

EPSS

Процентиль: 3%
0.00017
Низкий

4.2 Medium

CVSS3