CVE-2020-14039
—CVSS 3.1
5.3 medium
EPSS
2%p77
Published
()
Modified
Description
In Go before 1.13.13 and 1.14.x before 1.14.5, Certificate.Verify may lack a check on the VerifyOptions.KeyUsages EKU requirements (if VerifyOptions.Roots equals nil and the installation is on Windows). Thus, X.509 certificate verification is incomplete.
In the news0 stories
No ingested article mentions this CVE yet.