Lucene search

K
ibmIBM5F5D3CEFEA884B6709DBD49D40D3E975A798FDFD2E04275C70BC4CA8663DFC57
HistoryAug 20, 2020 - 7:29 p.m.

Security Bulletin: Golang Vulnerabilities in IBM Cloud CLI 1.1.0 or earlier

2020-08-2019:29:57
www.ibm.com
17
golang
ibm cloud cli
vulnerabilities
denial of service
security bypass
cve-2020-15586
cve-2020-14039
upgrade

EPSS

0.011

Percentile

84.4%

Summary

Golang vulnerabilities were found, which could allow an attacker to bypass security restrictions under some circumstances. IBM Cloud CLI version 1.1.0 or earlier is impacted by these vulnerabilities.

Vulnerability Details

CVEID:CVE-2020-15586
**DESCRIPTION:**Golang Go is vulnerable to a denial of service, caused by a data race in some net/http servers. By sending specially-crafted HTTP requests, a remote attacker could exploit this vulnerability to cause a denial of service condition.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/185446 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

CVEID:CVE-2020-14039
**DESCRIPTION:**Go could allow a remote attacker to bypass security restrictions, caused by improper validation on the VerifyOptions.KeyUsages EKU requirements during the X.509 certificate verification. An attacker could exploit this vulnerability to gain access to the system.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/185443 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Cloud CLI 1.1.0 or earlier

Remediation/Fixes

Upgrade IBM Cloud CLI to version 1.2.0 or later.

Workarounds and Mitigations

None