CVE-2020-7919

Aliases:GHSA-cjjc-xp8v-855wBIT-golang-2020-7919GO-2022-0229CGA-647p-f32r-44jmCGA-6wjw-xxw2-8hw3CGA-gjwv-r95w-97j2CGA-h3r3-5gfc-7j78CGA-jvh2-vmr3-v5x8CGA-chpw-9gx8-5j8hCGA-qm3g-g472-xq82CGA-rgm8-wqp4-9mjw
Advisory lineage Upstream: 0 Downstream: 3
Modified
Published: 16 Mar 2020, 20:55
Last modified:04 Aug 2024, 09:48

Vulnerability Summary

Overall Risk (default)
medium
32/100
CVSS Score
7.8 HIGH
v2.0 (nvd)
EPSS Score
2.65% LOW
3% probability +1.80%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

16 Mar 2020, 20:55
Published
Vulnerability first disclosed
04 Aug 2024, 09:48
Last Modified
Vulnerability information updated

Description

Go before 1.12.16 and 1.13.x before 1.13.7 (and the crypto/cryptobyte package before 0.0.0-20200124225646-8b5121be2f68 for Go) allows attacks on clients (resulting in a panic) via a malformed X.509 certificate.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • v2.0HIGHScore: 7.8AV:N/AC:L/Au:N/C:N/I:N/A:C

EPSS Trends

Current EPSS score: 2.65% Percentile: 85%

Techniques & Countermeasures

  • CWE-295Improper Certificate Validation

    The product does not validate, or incorrectly validates, a certificate.

Affected Systems

  • chainguarddex-k8s-authenticator

    < 1.4.0-r35

  • chainguardk3d

    < 5.6.0-r11

  • chainguardk3d-proxy

    < 5.6.0-r11

  • chainguardk3d-tools

    < 5.6.0-r11

  • wolfik3d

    < 5.6.0-r11

  • wolfik3d-proxy

    < 5.6.0-r11

  • wolfik3d-tools

    < 5.6.0-r11

  • debiandebian_linux

    10.0

  • fedoraprojectfedora

    31

  • github.com/helmhelm

    ≥ 2.0.0, < 2.16.8

  • golanggo

    ≥ 1.12, < 1.12.6 | ≥ 1.13, < 1.13.7

  • golang.org/xcrypto

    < 0.0.0-20200124225646-8b5121be2f68

  • helm.sh/helmv3

    ≥ 3.0.0, < 3.1.0

  • Gostdlib

    ≥ 1.13.0-0, < 1.13.7

  • netappcloud_insights_telegraf

    na

References (21)