CVE-2020-28362Improper Certificate Validation in Ethereum Go-ethereum

Severity
7.5HIGHNVD
EPSS
0.2%
top 62.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 18
Latest updateAug 21

Description

Go before 1.14.12 and 1.15.x before 1.15.4 allows Denial of Service.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

NVDgolang/go1.151.15.5+1

Also affects: Fedora 32, 33

🔴Vulnerability Details

7
OSV
Denial of service in go-ethereum due to CVE-2020-28362 in github.com/ethereum/go-ethereum2024-08-21
GHSA
GHSA-gff4-9rfx-4pcw: Go before 12022-05-24
GHSA
Denial of service in go-ethereum due to CVE-2020-283622021-06-29
OSV
Denial of service in go-ethereum due to CVE-2020-283622021-06-29
OSV
Panic during division of very large numbers in math/big2021-04-14

📋Vendor Advisories

3
Red Hat
golang: math/big: panic during recursive division of very large numbers2020-11-12
Microsoft
Go before 1.14.12 and 1.15.x before 1.15.4 allows Denial of Service.2020-11-10
Debian
CVE-2020-28362: golang-1.15 - Go before 1.14.12 and 1.15.x before 1.15.4 allows Denial of Service.2020
CVE-2020-28362 — Improper Certificate Validation | cvebase