A flaw was found in krb5 certificate EKU validation which could lead to improper authorization if a forged certificate with the right EKU and no SAN is used. https://nvd.nist.gov/vuln/detail/CVE-2017-7562