VYPR

Bitnami package

golang

pkg:bitnami/golang

Vulnerabilities (183)

  • CVE-2020-14039MedJul 17, 2020
    affected < 1.13.13fixed 1.13.13

    In Go before 1.13.13 and 1.14.x before 1.14.5, Certificate.Verify may lack a check on the VerifyOptions.KeyUsages EKU requirements (if VerifyOptions.Roots equals nil and the installation is on Windows). Thus, X.509 certificate verification is incomplete.

  • CVE-2020-7919HigMar 16, 2020
    affected >= 1.12.0, < 1.12.6fixed 1.12.6

    Go before 1.12.16 and 1.13.x before 1.13.7 (and the crypto/cryptobyte package before 0.0.0-20200124225646-8b5121be2f68 for Go) allows attacks on clients (resulting in a panic) via a malformed X.509 certificate.

  • CVE-2020-0601HigKEVJan 14, 2020
    affected >= 1.12.0, < 1.12.16fixed 1.12.16

    A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file wa

Page 10 of 10