Lucene search

K
redhatcveRedhat.comRH:CVE-2024-24783
HistoryMar 06, 2024 - 3:33 a.m.

CVE-2024-24783

2024-03-0603:33:39
redhat.com
access.redhat.com
21
crypto library
certificate chain verification
public key algorithm
tls clients and servers
config.clientauth

7.2 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.4%

A flaw was found in Go’s crypto/x509 standard library package. Verifying a certificate chain that contains a certificate with an unknown public key algorithm will cause a Certificate.Verify to panic. This issue affects all crypto/tls clients and servers that set Config.ClientAuth to VerifyClientCertIfGiven or RequireAndVerifyClientCert.

Mitigation

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.