Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-24784

Опубликовано: 05 мар. 2024
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

The ParseAddressList function incorrectly handles comments (text within parentheses) within display names. Since this is a misalignment with conforming address parsers, it can result in different trust decisions being made by programs using different parsers.

A flaw was found in Go's net/mail standard library package. The ParseAddressList function incorrectly handles comments (text within parentheses) within display names. Since this is a misalignment with conforming address parsers, it can result in different trust decisions made by programs using different parsers.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
cert-manager Operator for Red Hat OpenShiftcert-manager/cert-manager-operator-rhel9Not affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/logging-loki-rhel8Not affected
Logical Volume Manager Storagelvms4/lvms-rhel9-operatorNot affected
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-validation-rhel9Affected
Multicluster Engine for Kubernetesmulticluster-engine/hive-rhel8Will not fix
OpenShift Developer Tools and ServiceshelmAffected
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel8Will not fix
OpenShift Pipelinesopenshift-pipelines-clientAffected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/thanos-rhel7Not affected
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-main-rhel8Out of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-115
https://bugzilla.redhat.com/show_bug.cgi?id=2268021golang: net/mail: comments in display names are incorrectly handled

EPSS

Процентиль: 80%
0.01498
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 1 года назад

The ParseAddressList function incorrectly handles comments (text within parentheses) within display names. Since this is a misalignment with conforming address parsers, it can result in different trust decisions being made by programs using different parsers.

CVSS3: 7.5
nvd
больше 1 года назад

The ParseAddressList function incorrectly handles comments (text within parentheses) within display names. Since this is a misalignment with conforming address parsers, it can result in different trust decisions being made by programs using different parsers.

CVSS3: 7.5
debian
больше 1 года назад

The ParseAddressList function incorrectly handles comments (text withi ...

CVSS3: 7.5
github
больше 1 года назад

The ParseAddressList function incorrectly handles comments (text within parentheses) within display names. Since this is a misalignment with conforming address parsers, it can result in different trust decisions being made by programs using different parsers.

CVSS3: 7.3
fstec
больше 1 года назад

Уязвимость функции ParseAddressList пакета net/mail языка программирования Go, позволяющая нарушителю выполнить спуфинг-атаки

EPSS

Процентиль: 80%
0.01498
Низкий

5.4 Medium

CVSS3

Уязвимость CVE-2024-24784