Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2022-1705

Опубликовано: 16 авг. 2022
Источник: msrc
CVSS3: 6.5
EPSS Низкий

Описание

Improper sanitization of Transfer-Encoding headers in net/http

EPSS

Процентиль: 17%
0.00055
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 3 лет назад

Acceptance of some invalid Transfer-Encoding headers in the HTTP/1 client in net/http before Go 1.17.12 and Go 1.18.4 allows HTTP request smuggling if combined with an intermediate server that also improperly fails to reject the header as invalid.

CVSS3: 6.5
redhat
больше 3 лет назад

Acceptance of some invalid Transfer-Encoding headers in the HTTP/1 client in net/http before Go 1.17.12 and Go 1.18.4 allows HTTP request smuggling if combined with an intermediate server that also improperly fails to reject the header as invalid.

CVSS3: 6.5
nvd
больше 3 лет назад

Acceptance of some invalid Transfer-Encoding headers in the HTTP/1 client in net/http before Go 1.17.12 and Go 1.18.4 allows HTTP request smuggling if combined with an intermediate server that also improperly fails to reject the header as invalid.

CVSS3: 6.5
debian
больше 3 лет назад

Acceptance of some invalid Transfer-Encoding headers in the HTTP/1 cli ...

CVSS3: 6.5
github
больше 3 лет назад

Acceptance of some invalid Transfer-Encoding headers in the HTTP/1 client in net/http before Go 1.17.12 and Go 1.18.4 allows HTTP request smuggling if combined with an intermediate server that also improperly fails to reject the header as invalid.

EPSS

Процентиль: 17%
0.00055
Низкий

6.5 Medium

CVSS3