摘要:
In Go before 1.13.13 and 1.14.x before 1.14.5, Certificate.Verify may lack a check on the VerifyOptions.KeyUsages EKU requirements (if VerifyOptions.Roots equals nil and the installation is on Windows). Thus, X.509 certificate verification is incomplete.
安全等级: Low
公告ID: KylinSec-SA-2022-1679
发布日期: 2022年7月30日
关联CVE: CVE-2020-14039
In Go before 1.13.13 and 1.14.x before 1.14.5, Certificate.Verify may lack a check on the VerifyOptions.KeyUsages EKU requirements (if VerifyOptions.Roots equals nil and the installation is on Windows). Thus, X.509 certificate verification is incomplete.
cve名称 | 产品 | 组件 | 是否受影响 |
---|---|---|---|
CVE-2020-14039 | KY3.4-4A | golang | Unaffected |
CVE-2020-14039 | KY3.4-5A | golang | Unaffected |
CVE-2020-14039 | KY3.5.1 | golang | Unaffected |