CVE-2017-1000097

Severity CVSS v4.0:
Pending analysis
Type:
CWE-295 Improper Certificate Validation
Publication date:
05/10/2017
Last modified:
20/04/2025

Description

On Darwin, user's trust preferences for root certificates were not honored. If the user had a root certificate loaded in their Keychain that was explicitly not trusted, a Go program would still verify a connection using that root certificate.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:golang:go:*:*:*:*:*:*:*:* 1.6.4 (excluding)
cpe:2.3:a:golang:go:*:*:*:*:*:*:*:* 1.7 (including) 1.7.4 (excluding)