PT-2014-7824 · Google+2 · Go+2

Publicado

2014-10-07

·

Atualizado

2024-06-15

·

CVE-2014-7189

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Go versions 1.1 through 1.3.2
Description The issue allows man-in-the-middle attackers to spoof clients via unspecified vectors when SessionTicketsDisabled is enabled. This can occur when the server enables TLS client authentication using certificates and explicitly sets SessionTicketsDisabled to true in the tls.Config, allowing a malicious client to falsely assert ownership of any client certificate.
Recommendations For Go versions 1.1 through 1.3.2, update to version 1.3.2 or later to resolve the issue. As a temporary workaround, consider disabling TLS client authentication using certificates or setting SessionTicketsDisabled to false in the tls.Config to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2015-1421
CVE-2014-7189
GO-2021-0154
MGASA-2014-0410
OPENSUSE-SU-2024:10028-1
OPENSUSE-SU-2024:10803-1
OPENSUSE-SU-2024:10804-1
OPENSUSE-SU-2024:10805-1
OPENSUSE-SU-2024:10811-1
OPENSUSE-SU-2024:10812-1

Produtos afetados

Alt Linux
Go
Suse