Improper Certificate Validation in Go programming language - CVE-2020-14039
Published: July 27, 2020
Vulnerability identifier: #VU31890
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-14039
CWE-ID: CWE-295
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists when "VerifyOptions.Roots" is nil, "Certificate.Verify" does not check the EKU requirements specified in "VerifyOptions.KeyUsages".
Affected software
Go programming language
ObjectScale
Dell PowerProtect Cyber Recovery
QRadar Suite
Opensuse
IBM Robotic Process Automation
Netcool Operations Insight
ObjectScale
Dell PowerProtect Cyber Recovery
QRadar Suite
Opensuse
IBM Robotic Process Automation
Netcool Operations Insight
How to mitigate CVE-2020-14039
Install updates from vendor's website.
Go programming language - addressed in versions 1.13.13, 1.14.5
ObjectScale - update to 1.3.0
QRadar Suite - update to 1.10.17.0
IBM Robotic Process Automation - update to 21.0.3.1
Netcool Operations Insight - update to 1.6.6
Dell PowerProtect Cyber Recovery - update to 19.14.0.1
ObjectScale - update to 1.3.0
QRadar Suite - update to 1.10.17.0
IBM Robotic Process Automation - update to 21.0.3.1
Netcool Operations Insight - update to 1.6.6
Dell PowerProtect Cyber Recovery - update to 19.14.0.1
External References
Related Security Bulletins
- OpenSUSE Linux update for go1.13
- Multiple vulnerabilities in Go
- OpenSUSE Linux update for go1.13
- OpenSUSE Linux update for go1.14
- OpenSUSE Linux update for go1.14
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in Dell PowerProtect Cyber Recovery
- Multiple vulnerabilities in IBM QRadar Suite software
- Multiple vulnerabilities in Dell ObjectScale