CVE-2020-7919 PUBLISHED

Go before 1.12.16 and 1.13.x before 1.13.7 (and the crypto/cryptobyte package before 0.0.0-20200124225646-8b5121be2f68 for Go) allows attacks on clients (resulting in a panic) via a malformed X.509 certificate.

EPSS 0.65% · 70.7th percentile

Risk Scores

EPSS Score
0.65%
70.7th percentile

Affected Products

VendorProductVersions
Bitnamigolang1.12.0, 1.13.0
Bitnamigolang1.12.0, 1.13.0

Timeline

References

Open in Interactive Console →