VDB
Sign up
—

GO-2022-0535

Certificate validation bypass on Windows in crypto/x509

Quick fix

GO-2022-0535 — stdlib: upgrade to the fixed version with the command below.

go get stdlib@v1.12.16

Details

A Windows vulnerability allows attackers to spoof valid certificate chains when the system root store is in use.

A workaround is present in Go 1.12.6+ and Go 1.13.7+, but affected users should additionally install the Windows security update to protect their system.

See https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2020-0601 for details on the Windows vulnerability.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/stdlib
Introduced in: 0Fixed in: 1.12.16
Fixgo get stdlib@v1.12.16

References