Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-28851

Опубликовано: 02 янв. 2021
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

In x/text in Go 1.15.4, an "index out of range" panic occurs in language.ParseAcceptLanguage while parsing the -u- extension. (x/text/language is supposed to be able to parse an HTTP Accept-Language header.)

A flaw was found in golang.org. In x/text, an "index out of range" panic occurs in language.ParseAcceptLanguage while parsing the -u- extension.

Отчет

Below Red Hat products include the affected version of 'golang.org/x/text', however the language package is not being used and hence they are rated as having a security impact of Low. A future update may address this issue.

  • Red Hat OpenShift Container Storage 4
  • OpenShift ServiceMesh (OSSM)
  • Red Hat Gluster Storage 3
  • Windows Container Support for Red Hat OpenShift Only three components in OpenShift Container Platform include the affected package, 'golang.org/x/text/language' , the installer, baremetal installer and thanos container images. All other components that include a version of 'golang.org/x/text' do not include the 'language' package and are therefore not affected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Service Mesh 2.0servicemesh-cniWill not fix
Red Hat Ceph Storage 2golangOut of support scope
Red Hat Ceph Storage 3golangAffected
Red Hat Developer Toolsgo-toolset-1.14-golangNot affected
Red Hat Enterprise Linux 7buildahOut of support scope
Red Hat Enterprise Linux 7golangOut of support scope
Red Hat Enterprise Linux 7podmanOut of support scope
Red Hat Enterprise Linux 8container-tools:1.0/buildahWill not fix
Red Hat Enterprise Linux 8container-tools:1.0/podmanOut of support scope
Red Hat Enterprise Linux 8container-tools:2.0/buildahWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-129
https://bugzilla.redhat.com/show_bug.cgi?id=1913333golang.org/x/text: Panic in language.ParseAcceptLanguage while parsing -u- extension

EPSS

Процентиль: 25%
0.00082
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 4 лет назад

In x/text in Go 1.15.4, an "index out of range" panic occurs in language.ParseAcceptLanguage while parsing the -u- extension. (x/text/language is supposed to be able to parse an HTTP Accept-Language header.)

CVSS3: 7.5
nvd
больше 4 лет назад

In x/text in Go 1.15.4, an "index out of range" panic occurs in language.ParseAcceptLanguage while parsing the -u- extension. (x/text/language is supposed to be able to parse an HTTP Accept-Language header.)

CVSS3: 7.5
msrc
9 месяцев назад

Описание отсутствует

CVSS3: 7.5
debian
больше 4 лет назад

In x/text in Go 1.15.4, an "index out of range" panic occurs in langua ...

github
около 3 лет назад

In x/text in Go 1.15.4, an "index out of range" panic occurs in language.ParseAcceptLanguage while parsing the -u- extension. (x/text/language is supposed to be able to parse an HTTP Accept-Language header.)

EPSS

Процентиль: 25%
0.00082
Низкий

7.5 High

CVSS3

Уязвимость CVE-2020-28851