CVE-2024-45341

Published: January 23, 2025Last modified: August 31, 2026

Description

A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that applies to the certificate chain. Certificates containing URIs are not permitted in the web PKI, so this only affects users of private PKIs which make use of URIs.

Severity score breakdown

ParameterValue
Base score6.1
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionREQUIRED
ScopeCHANGED
ConfidentialityLOW
Integrity impactLOW
Availability impactNONE
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSgoFixed (1.21.12-r3)
25 LTSgoNot affected (1.24.3-r0)
StreamgoFixed (1.23.5-r0)
Hardened Containers23 LTSgoFixed (1.21.12-r3)
25 LTSgoNot affected (1.24.3-r0)
StreamgoFixed (1.23.5-r0)

References

ON THIS PAGE