PoC Index

CVE-2021-34558

MEDIUM 6.5EPSS 7.0%

The crypto/tls package of Go through 1.16.5 does not properly assert that the type of public key in an X.509 certificate matches the expected type when doing a RSA based key exchange, allowing a malicious TLS server to cause a TLS client to panic.

CVSS v3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS v2.0
2.6 LOWAV:N/AC:H/Au:N/C:N/I:N/A:P
EPSS
6.98% chance of exploitation in the next 30 days, 94th percentile
Published
2021-07-15
Updated
2024-08-04

Proof-of-concept exploits (1)

References

Related