Launch Week Day 1: Announcing Security Design Review
UNKNOWN Go

Mishandled trust preferences for root certificates on Darwin in crypto/x509

GO-2022-0171 · CVE-2017-1000097

Published · Modified

Description

On Darwin, user's trust preferences for root certificates were not honored. If the user had a root certificate loaded in their Keychain that was explicitly not trusted, a Go program would still verify a connection using that root certificate.

Ready to move

Start Securing

Free, no credit card | First findings in minutes