Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-22874

Опубликовано: 11 июн. 2025
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. This only affected certificate chains which contain policy graphs, which are rather uncommon.

A flaw was found in Go's crypto/x509 package. This vulnerability allows improper certificate validation, bypassing policy constraints via using ExtKeyUsageAny in VerifyOptions.KeyUsages.

Отчет

This flaw is rated as an Important severity because the vulnerability was found in the certificate validation logic of the Verify function. When VerifyOptions.KeyUsages includes ExtKeyUsageAny, certificate chains containing policy graphs may bypass certificate policy validation. This flaw allows an attacker to trick the system into accepting an invalid certificate, potentially enabling spoofing attacks, the issue weakens trust decisions in affected cases and impacts system integrity. Confidentiality and availability are not affected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Assisted Installer for Red Hat OpenShift Container Platform 2rhai/assisted-installer-agent-rhel9Affected
Assisted Installer for Red Hat OpenShift Container Platform 2rhai/assisted-installer-controller-rhel9Affected
Assisted Installer for Red Hat OpenShift Container Platform 2rhai/assisted-installer-rhel9Affected
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-controller-rhel9Will not fix
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-git-cloner-rhel9Will not fix
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-image-bundler-rhel9Will not fix
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-image-processing-rhel9Will not fix
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-rhel9-operatorAffected
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-shared-resource-rhel9Will not fix
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-shared-resource-webhook-rhel9Will not fix

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-295
https://bugzilla.redhat.com/show_bug.cgi?id=2372320crypto/x509: Usage of ExtKeyUsageAny disables policy validation in crypto/x509

EPSS

Процентиль: 1%
0.00012
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
5 месяцев назад

Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. This only affected certificate chains which contain policy graphs, which are rather uncommon.

CVSS3: 7.5
nvd
5 месяцев назад

Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. This only affected certificate chains which contain policy graphs, which are rather uncommon.

CVSS3: 7.5
msrc
4 месяца назад

Usage of ExtKeyUsageAny disables policy validation in crypto/x509

CVSS3: 7.5
debian
5 месяцев назад

Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsag ...

CVSS3: 7.5
github
5 месяцев назад

Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. This only affected certificate chains which contain policy graphs, which are rather uncommon.

EPSS

Процентиль: 1%
0.00012
Низкий

7.5 High

CVSS3