Описание
net/http in Go before 1.15.12 and 1.16.x before 1.16.4 allows remote attackers to cause a denial of service (panic) via a large header to ReadRequest or ReadResponse. Server, Transport, and Client can each be affected in some configurations.
A vulnerability was detected in net/http of the Go standard library when parsing very large HTTP header values, causing a crash and subsequent denial of service. This vulnerability affects both clients and servers written in Go, however, servers are only vulnerable if the value of MaxHeaderBytes has been increased from the default.
Отчет
This vulnerability potentially affects any component written in Go that uses net/http from the standard library. In OpenShift Container Platform (OCP), OpenShift Virtualization, OpenShift ServiceMesh (OSSM) and OpenShift distributed tracing (formerly OpenShift Jaeger), no server side component allows HTTP header values larger than 1 MB (the default), preventing this vulnerability from being exploited by malicious clients. It is possible for components that make client connections to malicious servers to be exploited, however the maximum impact is a crash. This vulnerability is rated Low for the following components:
- OpenShift Container Platform
- OpenShift Virtualization
- OpenShift ServiceMesh
- OpenShift distributed tracing components.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Migration Toolkit for Containers | rhmtc/openshift-migration-rhel8-operator | Affected | ||
OpenShift Serverless | CLI | Affected | ||
OpenShift Serverless | knative-eventing | Affected | ||
OpenShift Service Mesh 2.0 | servicemesh | Affected | ||
OpenShift Service Mesh 2.0 | servicemesh-grafana | Affected | ||
OpenShift Service Mesh 2.0 | servicemesh-operator | Will not fix | ||
OpenShift Service Mesh 2.0 | servicemesh-prometheus | Affected | ||
Red Hat Ceph Storage 2 | golang | Out of support scope | ||
Red Hat Ceph Storage 2 | grafana | Out of support scope | ||
Red Hat Ceph Storage 3 | golang | Out of support scope |
Показывать по
Дополнительная информация
Статус:
EPSS
5.9 Medium
CVSS3
Связанные уязвимости
net/http in Go before 1.15.12 and 1.16.x before 1.16.4 allows remote attackers to cause a denial of service (panic) via a large header to ReadRequest or ReadResponse. Server, Transport, and Client can each be affected in some configurations.
net/http in Go before 1.15.12 and 1.16.x before 1.16.4 allows remote attackers to cause a denial of service (panic) via a large header to ReadRequest or ReadResponse. Server, Transport, and Client can each be affected in some configurations.
net/http in Go before 1.15.12 and 1.16.x before 1.16.4 allows remote a ...
EPSS
5.9 Medium
CVSS3