HomeDefault status
unaffected
1.24.0-0 (semver) before 1.24.4
affected
Description
Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. This only affected certificate chains which contain policy graphs, which are rather uncommon.
Problem types
CWE-295: Improper Certificate Validation
Product status
1.24.0-0 (semver) before 1.24.4
Credits
Krzysztof Skrzętnicki (@Tener) of Teleport
References
groups.google.com/g/golang-announce/c/ufZ8WpEsA3A