Mariner
CVE-2021-34558 — The crypto/tls package of Go through 1.16.5 does not properly assert that the type of public key in an X.509 certificate matches the expected type when doing a RSA based key exchange allowing a malicious TLS server to cause a TLS client to panic.
Executive Summary
None
Overview
6.5
CVSS MEDIUM
Moderate
MS Severity
Not Exploited
MS Exploit Status
N/A
MS Exploit Likelihood
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
ATTACK VECTOR
Network
ATTACK COMPLEXITY
Low
PRIVILEGES REQUIRED
None
USER INTERACTION
Required
SCOPE
Unchanged
CONFIDENTIALITY
None
INTEGRITY
None
AVAILABILITY
High
Temporal Score: 6.5
EPSS Score
No EPSS score available for this CVE.
View on FIRST.orgAffected Products
1 affected product
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| cm1 golang 1.16.7-1 on CBL Mariner 1.0 | CBL-Mariner Releases (Security Update) |
Moderate | No |
Patches
1 patch
| Article | Type | Restart |
|---|---|---|
CBL-Mariner Releases |
Security Update | No |
Known Exploits
No known exploits have been linked for this CVE yet. When available, exploit references will be sourced from public repositories and may be unverified, incomplete, or non-functional. Always review code carefully before use in any environment.
Acknowledgments
Microsoft has not published researcher acknowledgments for this CVE, or they are not yet reflected in our data source. Check the MSRC advisory directly for the most current credit information.
References
On This Page