Описание
github.com/pires/go-proxyproto vulnerable to DoS via Connection descriptor exhaustion
The package github.com/pires/go-proxyproto before 0.6.1 is vulnerable to Denial of Service (DoS) via creating connections without the proxy protocol header. While this issue was patched in 0.6.0, the fix introduced additional issues which were subsequently patched in 0.6.1.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2021-23409
- https://github.com/pires/go-proxyproto/issues/65
- https://github.com/pires/go-proxyproto/issues/75
- https://github.com/pires/go-proxyproto/pull/74
- https://github.com/pires/go-proxyproto/pull/74/commits/cdc63867da24fc609b727231f682670d0d1cd346
- https://github.com/pires/go-proxyproto/pull/76
- https://github.com/pires/go-proxyproto/commit/2e44d7a76a851d66890ab341403253afae5caac2
- https://github.com/pires/go-proxyproto/releases/tag/v0.6.0
- https://github.com/pires/go-proxyproto/releases/tag/v0.6.1
- https://pkg.go.dev/vuln/GO-2022-0233
- https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMPIRESGOPROXYPROTO-1316439
Пакеты
github.com/pires/go-proxyproto
< 0.6.1
0.6.1
Связанные уязвимости
The package github.com/pires/go-proxyproto before 0.6.0 are vulnerable to Denial of Service (DoS) via creating connections without the proxy protocol header.
The package github.com/pires/go-proxyproto before 0.6.0 are vulnerable to Denial of Service (DoS) via creating connections without the proxy protocol header.
The package github.com/pires/go-proxyproto before 0.6.0 are vulnerable ...
Уязвимость библиотеки протокола PROXY языка golang Go-proxyproto, позволяющая нарушителю вызвать отказ в обслуживании