logo

CVE-2024-45341 stdlib

Package

Manager: go
Name: stdlib
Vulnerable Version: >=0 <1.22.11

Severity

Level: Low

CVSS v3.1: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N/E:P/RL:O/RC:C

CVSS v4.0: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N

EPSS: 0.00032 pctl0.07518

Details

Usage of IPv6 zone IDs can bypass URI name constraints in crypto/x509 A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that applies to the certificate chain. Certificates containing URIs are not permitted in the web PKI, so this only affects users of private PKIs which make use of URIs.

Metadata

Created: 2025-01-28T00:47:30Z
Modified: 2025-01-30T20:12:14.327943Z
Source: https://osv-vulnerabilities
CWE IDs: N/A
Alternative ID: N/A
Finding: F163
Auto approve: 1