Vulnerability Report: GO-2022-0535

standard library

A Windows vulnerability allows attackers to spoof valid certificate chains when the system root store is in use. A workaround is present in Go 1.12.6+ and Go 1.13.7+, but affected users should additionally install the Windows security update to protect their system. See https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2020-0601 for details on the Windows vulnerability.

Affected Packages

  • Path
    Versions
    Symbols
  • before go1.12.16, from go1.13.0-0 before go1.13.7
    1 unexported affected symbols
    • Certificate.systemVerify

Aliases

References

Feedback

See anything missing or incorrect? Suggest an edit to this report.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL