Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2025:10672

Опубликовано: 29 июл. 2025
Источник: rocky
Оценка: Moderate

Описание

Moderate: go-toolset:rhel8 security update

Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang.

Security Fix(es):

  • net/http: Sensitive headers not cleared on cross-origin redirect in net/http (CVE-2025-4673)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
delvex86_641.module+el8.10.0+1951+c74bd827delve-1.24.1-1.module+el8.10.0+1951+c74bd827.x86_64.rpm
delvex86_641.module+el8.10.0+1987+42f155bbdelve-1.24.1-1.module+el8.10.0+1987+42f155bb.x86_64.rpm
golangx86_641.module+el8.10.0+2008+0bb8dc3egolang-1.24.4-1.module+el8.10.0+2008+0bb8dc3e.x86_64.rpm
golang-binx86_641.module+el8.10.0+2008+0bb8dc3egolang-bin-1.24.4-1.module+el8.10.0+2008+0bb8dc3e.x86_64.rpm
golang-docsnoarch1.module+el8.10.0+2008+0bb8dc3egolang-docs-1.24.4-1.module+el8.10.0+2008+0bb8dc3e.noarch.rpm
golang-docsnoarch1.module+el8.10.0+2008+0bb8dc3egolang-docs-1.24.4-1.module+el8.10.0+2008+0bb8dc3e.noarch.rpm
golang-miscnoarch1.module+el8.10.0+2008+0bb8dc3egolang-misc-1.24.4-1.module+el8.10.0+2008+0bb8dc3e.noarch.rpm
golang-miscnoarch1.module+el8.10.0+2008+0bb8dc3egolang-misc-1.24.4-1.module+el8.10.0+2008+0bb8dc3e.noarch.rpm
golang-srcnoarch1.module+el8.10.0+2008+0bb8dc3egolang-src-1.24.4-1.module+el8.10.0+2008+0bb8dc3e.noarch.rpm
golang-srcnoarch1.module+el8.10.0+2008+0bb8dc3egolang-src-1.24.4-1.module+el8.10.0+2008+0bb8dc3e.noarch.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 6.8
ubuntu
8 месяцев назад

Proxy-Authorization and Proxy-Authenticate headers persisted on cross-origin redirects potentially leaking sensitive information.

CVSS3: 6.8
redhat
8 месяцев назад

Proxy-Authorization and Proxy-Authenticate headers persisted on cross-origin redirects potentially leaking sensitive information.

CVSS3: 6.8
nvd
8 месяцев назад

Proxy-Authorization and Proxy-Authenticate headers persisted on cross-origin redirects potentially leaking sensitive information.

CVSS3: 6.8
msrc
7 месяцев назад

Sensitive headers not cleared on cross-origin redirect in net/http

CVSS3: 6.8
debian
8 месяцев назад

Proxy-Authorization and Proxy-Authenticate headers persisted on cross- ...