4.3
CVSSv2

CVE-2014-7189

Published: 07/10/2014 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

crpyto/tls in Go 1.1 prior to 1.3.2, when SessionTicketsDisabled is enabled, allows man-in-the-middle malicious users to spoof clients via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

golang go 1.2.1

golang go 1.3

golang go 1.2

golang go 1.2.2

golang go 1.1

golang go 1.1.1

golang go 1.1.2

golang go 1.3.1

Vendor Advisories

crpyto/tls in Go 11 before 132, when SessionTicketsDisabled is enabled, allows man-in-the-middle attackers to spoof clients via unspecified vectors ...