DirectorySecurity Advisories
Sign In
Security Advisories

CVE-2024-24783

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2024-24783

CGA ID

CGA-g8hr-2vg2-m8rq

Description

Verifying a certificate chain which contains a certificate with an unknown public key algorithm will cause Certificate.Verify to panic. This affects all crypto/tls clients, and servers that set Config.ClientAuth to VerifyClientCertIfGiven or RequireAndVerifyClientCert. The default behavior is for TLS servers to not verify client certificates.

References

Affected packages


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images