Improper Certificate Validation in Go programming language - CVE-2020-14039

 

Improper Certificate Validation in Go programming language - CVE-2020-14039

Published: July 27, 2020


Vulnerability identifier: #VU31890
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-14039
CWE-ID: CWE-295
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists when "VerifyOptions.Roots" is nil, "Certificate.Verify" does not check the EKU requirements specified in "VerifyOptions.KeyUsages".


Affected software

Go programming language
ObjectScale
Dell PowerProtect Cyber Recovery
QRadar Suite
Opensuse
IBM Robotic Process Automation
Netcool Operations Insight

How to mitigate CVE-2020-14039

Install updates from vendor's website.

Go programming language - addressed in versions 1.13.13, 1.14.5
ObjectScale - update to 1.3.0
QRadar Suite - update to 1.10.17.0
IBM Robotic Process Automation - update to 21.0.3.1
Netcool Operations Insight - update to 1.6.6
Dell PowerProtect Cyber Recovery - update to 19.14.0.1

External References

Related Security Bulletins