—
GO-2022-0535
Certificate validation bypass on Windows in crypto/x509
Quick fix
GO-2022-0535 — stdlib: upgrade to the fixed version with the command below.
go get stdlib@v1.12.16Details
A Windows vulnerability allows attackers to spoof valid certificate chains when the system root store is in use.
A workaround is present in Go 1.12.6+ and Go 1.13.7+, but affected users should additionally install the Windows security update to protect their system.
See https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2020-0601 for details on the Windows vulnerability.
Are you affected?
Enter the version of the package you're using.