The TLS certificate authentication method incorrectly validates client certificates when configured with a non-CA certificate as a trusted certificate. When configured this way, attackers may be able to craft a certificate that can be used to bypass authentication.
{ "review_status": "REVIEWED", "url": "https://pkg.go.dev/vuln/GO-2024-2617" }