Mariner
CVE-2021-34558 — The crypto/tls package of Go through 1.16.5 does not properly assert that the type of public key in an X.509 certificate matches the expected type when doing a RSA based key exchange allowing a malicious TLS server to cause a TLS client to panic.
Executive Summary
None
Overview
6.5
CVSS MEDIUM
Moderate
MS Severity
Not Exploited
MS Exploit Status
N/A
MS Exploit Likelihood
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
ATTACK VECTOR
Network
ATTACK COMPLEXITY
Low
PRIVILEGES REQUIRED
None
USER INTERACTION
Required
SCOPE
Unchanged
CONFIDENTIALITY
None
INTEGRITY
None
AVAILABILITY
High
Temporal Score: 6.5
EPSS Score
No EPSS score available for this CVE.
View on FIRST.orgAffected Products
1 affected product
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| cm1 golang 1.16.7-1 on CBL Mariner 1.0 | CBL-Mariner Releases (Security Update) |
Moderate | No |
Patches
1 patch
| Article | Type | Restart |
|---|---|---|
CBL-Mariner Releases |
Security Update | No |
Exploits & PoC
1 public PoCUnverified third-party code
Public proof-of-concept repositories aggregated from PoC-in-GitHub. They are not reviewed and may be incomplete, non-functional, or malicious — inspect the code before running anything.
| Repository | Stars | Published | Description |
|---|---|---|---|
| alexzorin/cve-2021-34558 | 45 | 2021-07-13 |
Detection Rules
No public Sigma or Nuclei detection rule has been mapped to this CVE yet. Coverage is concentrated on exploited / high-profile vulnerabilities; check SigmaHQ for updates.
Acknowledgments
Microsoft has not published researcher acknowledgments for this CVE, or they are not yet reflected in our data source. Check the MSRC advisory directly for the most current credit information.
References
On This Page