Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-24553

Опубликовано: 02 сент. 2020
Источник: debian

Описание

Go before 1.14.8 and 1.15.x before 1.15.1 allows XSS because text/html is the default for CGI/FCGI handlers that lack a Content-Type header.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-1.15fixed1.15.2-1package
golang-1.14removedpackage
golang-1.11removedpackage
golang-1.11postponedbusterpackage
golang-1.8removedpackage
golang-1.8no-dsastretchpackage
golang-1.7removedpackage
golang-1.7no-dsastretchpackage

Примечания

  • https://groups.google.com/forum/#!topic/golang-announce/8wqlSbkLdPs

  • https://github.com/golang/go/issues/40928

  • https://github.com/golang/go/issues/41164 (1.14 backport)

  • https://github.com/golang/go/issues/41165 (1.15 backport)

  • https://www.redteam-pentesting.de/en/advisories/rt-sa-2020-004/-inconsistent-behavior-of-gos-cgi-and-fastcgi-transport-may-lead-to-cross-site-scripting

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 5 лет назад

Go before 1.14.8 and 1.15.x before 1.15.1 allows XSS because text/html is the default for CGI/FCGI handlers that lack a Content-Type header.

CVSS3: 6.1
redhat
больше 5 лет назад

Go before 1.14.8 and 1.15.x before 1.15.1 allows XSS because text/html is the default for CGI/FCGI handlers that lack a Content-Type header.

CVSS3: 6.1
nvd
больше 5 лет назад

Go before 1.14.8 and 1.15.x before 1.15.1 allows XSS because text/html is the default for CGI/FCGI handlers that lack a Content-Type header.

CVSS3: 6.1
msrc
больше 5 лет назад

Описание отсутствует

suse-cvrf
больше 5 лет назад

Security update for go1.14