Описание
The package github.com/pires/go-proxyproto before 0.6.0 are vulnerable to Denial of Service (DoS) via creating connections without the proxy protocol header.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| golang-github-pires-go-proxyproto | fixed | 0.4.2-2 | package | |
| golang-github-pires-go-proxyproto | no-dsa | bullseye | package |
Примечания
https://github.com/pires/go-proxyproto/issues/65
https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMPIRESGOPROXYPROTO-1316439
https://github.com/pires/go-proxyproto/pull/74
EPSS
Связанные уязвимости
The package github.com/pires/go-proxyproto before 0.6.0 are vulnerable to Denial of Service (DoS) via creating connections without the proxy protocol header.
The package github.com/pires/go-proxyproto before 0.6.0 are vulnerable to Denial of Service (DoS) via creating connections without the proxy protocol header.
github.com/pires/go-proxyproto vulnerable to DoS via Connection descriptor exhaustion
Уязвимость библиотеки протокола PROXY языка golang Go-proxyproto, позволяющая нарушителю вызвать отказ в обслуживании
EPSS