First published: Mon Mar 16 2020(Updated: )
Go before 1.12.16 and 1.13.x before 1.13.7 (and the crypto/cryptobyte package before 0.0.0-20200124225646-8b5121be2f68 for Go) allows attacks on clients (resulting in a panic) via a malformed X.509 certificate.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
go/helm.sh/helm/v3 | >=3.0.0<3.1.0 | 3.1.0 |
go/golang.org/x/crypto | <0.0.0-20200124225646-8b5121be2f68 | 0.0.0-20200124225646-8b5121be2f68 |
go/github.com/helm/helm | >=2.0.0<2.16.8 | 2.16.8 |
debian/golang-1.11 | 1.11.6-1+deb10u4 1.11.6-1+deb10u7 | |
Golang Go | >=1.12<1.12.6 | |
Golang Go | >=1.13<1.13.7 | |
Debian Debian Linux | =10.0 | |
Fedoraproject Fedora | =31 | |
Netapp Cloud Insights Telegraf | ||
>=1.12<1.12.6 | ||
>=1.13<1.13.7 | ||
=10.0 | ||
=31 | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this security vulnerability is CVE-2020-7919.
The severity of CVE-2020-7919 is high (7.5).
Versions of Go's `crypto` package before 0.0.0-20200124225646-8b5121be2f68 are affected by CVE-2020-7919.
Versions of Helm prior to 2.16.8 and 3.1.0 are affected by CVE-2020-7919.
To fix CVE-2020-7919, update your version of Go's `crypto` package to 0.0.0-20200124225646-8b5121be2f68, or update Helm to version 2.16.8 or 3.1.0.