PT-2014-7824 · Google+2 · Go+2

Published

2014-10-07

·

Updated

2024-06-15

·

CVE-2014-7189

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Go versions 1.1 through 1.3.2
Description The issue allows man-in-the-middle attackers to spoof clients via unspecified vectors when SessionTicketsDisabled is enabled. This can occur when the server enables TLS client authentication using certificates and explicitly sets SessionTicketsDisabled to true in the tls.Config, allowing a malicious client to falsely assert ownership of any client certificate.
Recommendations For Go versions 1.1 through 1.3.2, update to version 1.3.2 or later to resolve the issue. As a temporary workaround, consider disabling TLS client authentication using certificates or setting SessionTicketsDisabled to false in the tls.Config to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1421
CVE-2014-7189
GO-2021-0154
MGASA-2014-0410
OPENSUSE-SU-2024:10028-1
OPENSUSE-SU-2024:10803-1
OPENSUSE-SU-2024:10804-1
OPENSUSE-SU-2024:10805-1
OPENSUSE-SU-2024:10811-1
OPENSUSE-SU-2024:10812-1

Affected Products

Alt Linux
Go
Suse