Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-28852

Опубликовано: 02 янв. 2021
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

In x/text in Go before v0.3.5, a "slice bounds out of range" panic occurs in language.ParseAcceptLanguage while processing a BCP 47 tag. (x/text/language is supposed to be able to parse an HTTP Accept-Language header.)

A flaw was found in golang.org. In x/text, a "slice bounds out of range" panic occurs in language.ParseAcceptLanguage while processing a BCP 47 tag.

Отчет

Below Red Hat products include the affected version of 'golang.org/x/text', however the language package is not being used and hence they are rated as having a security impact of Low. A future update may address this issue.

  • Red Hat OpenShift Container Storage 4
  • OpenShift ServiceMesh (OSSM)
  • Red Hat Gluster Storage 3
  • Windows Container Support for Red Hat OpenShift Only three components in OpenShift Container Platform include the affected package, 'golang.org/x/text/language' , the installer, baremetal installer and thanos container images. All other components that include a version of 'golang.org/x/text' do not include the 'language' package and are therefore not affected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Service Mesh 2.0servicemesh-cniWill not fix
Red Hat Ceph Storage 2golangOut of support scope
Red Hat Ceph Storage 3golangAffected
Red Hat Developer Toolsgo-toolset-1.14-golangNot affected
Red Hat Enterprise Linux 7buildahOut of support scope
Red Hat Enterprise Linux 7golangOut of support scope
Red Hat Enterprise Linux 7podmanOut of support scope
Red Hat Enterprise Linux 8container-tools:1.0/buildahWill not fix
Red Hat Enterprise Linux 8container-tools:1.0/podmanOut of support scope
Red Hat Enterprise Linux 8container-tools:2.0/buildahWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-129
https://bugzilla.redhat.com/show_bug.cgi?id=1913338golang.org/x/text: Panic in language.ParseAcceptLanguage while processing bcp47 tag

EPSS

Процентиль: 20%
0.00064
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 4 лет назад

In x/text in Go before v0.3.5, a "slice bounds out of range" panic occurs in language.ParseAcceptLanguage while processing a BCP 47 tag. (x/text/language is supposed to be able to parse an HTTP Accept-Language header.)

CVSS3: 7.5
nvd
больше 4 лет назад

In x/text in Go before v0.3.5, a "slice bounds out of range" panic occurs in language.ParseAcceptLanguage while processing a BCP 47 tag. (x/text/language is supposed to be able to parse an HTTP Accept-Language header.)

CVSS3: 7.5
msrc
9 месяцев назад

Описание отсутствует

CVSS3: 7.5
debian
больше 4 лет назад

In x/text in Go before v0.3.5, a "slice bounds out of range" panic occ ...

CVSS3: 7.5
github
около 3 лет назад

In x/text in Go 1.15.4, a "slice bounds out of range" panic occurs in language.ParseAcceptLanguage while processing a BCP 47 tag. (x/text/language is supposed to be able to parse an HTTP Accept-Language header.)

EPSS

Процентиль: 20%
0.00064
Низкий

7.5 High

CVSS3