Описание
In Go before 1.15.13 and 1.16.x before 1.16.5, some configurations of ReverseProxy (from net/http/httputil) result in a situation where an attacker is able to drop arbitrary headers.
A flaw was found in Go, acting as an unintended proxy or intermediary, where ReverseProxy forwards connection headers if the first one was empty. This flaw allows an attacker to drop arbitrary headers. The highest threat from this vulnerability is to integrity.
Отчет
- Since OpenShift Container Platform 3.11 is in Maintenance Phase of the support, only Important and Critical severity vulnerabilities will be addressed at this time.
- For Red Hat OpenStack Platform, because the flaw has a lower impact and the fix would require a substantial amount of development, no update will be provided at this time for the golang-qpid-apache package.
- In Service Telemetry Framework, because the flaw has a lower impact and the package is not directly used by STF, no updates will be provided at this time for the STF containers.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
OpenShift Serverless | knative-serving | Affected | ||
OpenShift Service Mesh 2.0 | servicemesh | Affected | ||
OpenShift Service Mesh 2.0 | servicemesh-grafana | Affected | ||
OpenShift Service Mesh 2.0 | servicemesh-operator | Will not fix | ||
OpenShift Service Mesh 2.0 | servicemesh-prometheus | Affected | ||
Red Hat Ceph Storage 2 | golang | Out of support scope | ||
Red Hat Ceph Storage 2 | grafana | Out of support scope | ||
Red Hat Ceph Storage 3 | golang | Out of support scope | ||
Red Hat Ceph Storage 3 | golang-github-prometheus-node_exporter | Out of support scope | ||
Red Hat Ceph Storage 3 | grafana | Out of support scope |
Показывать по
Дополнительная информация
Статус:
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
In Go before 1.15.13 and 1.16.x before 1.16.5, some configurations of ReverseProxy (from net/http/httputil) result in a situation where an attacker is able to drop arbitrary headers.
In Go before 1.15.13 and 1.16.x before 1.16.5, some configurations of ReverseProxy (from net/http/httputil) result in a situation where an attacker is able to drop arbitrary headers.
In Go before 1.15.13 and 1.16.x before 1.16.5, some configurations of ...
Go before 1.15.12 and 1.16.x before 1.16.5 acts as an Unintended Proxy or Intermediary.
EPSS
5.3 Medium
CVSS3