Описание
Acceptance of some invalid Transfer-Encoding headers in the HTTP/1 client in net/http before Go 1.17.12 and Go 1.18.4 allows HTTP request smuggling if combined with an intermediate server that also improperly fails to reject the header as invalid.
Релиз | Статус | Примечание |
---|---|---|
bionic | ignored | end of standard support |
devel | DNE | |
esm-apps/bionic | released | 1.13.8-1ubuntu1~18.04.4+esm1 |
esm-apps/jammy | released | 1.13.8-1ubuntu2.22.04.2 |
esm-apps/xenial | released | 1.13.8-1ubuntu1~16.04.3+esm3 |
esm-infra/focal | not-affected | 1.13.8-1ubuntu1.2 |
focal | released | 1.13.8-1ubuntu1.2 |
jammy | released | 1.13.8-1ubuntu2.22.04.2 |
lunar | DNE | |
mantic | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
bionic | ignored | end of standard support |
devel | DNE | |
esm-apps/bionic | released | 1.16.2-0ubuntu1~18.04.2+esm1 |
esm-apps/focal | released | 1.16.2-0ubuntu1~20.04.1 |
focal | released | 1.16.2-0ubuntu1~20.04.1 |
jammy | DNE | |
lunar | DNE | |
mantic | DNE | |
trusty | ignored | end of standard support |
upstream | needs-triage |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
bionic | released | 1.18.1-1ubuntu1~18.04.4 |
devel | DNE | |
esm-infra/focal | DNE | focal was released [1.18.1-1ubuntu1~20.04.2] |
focal | released | 1.18.1-1ubuntu1~20.04.2 |
impish | DNE | |
jammy | released | 1.18.1-1ubuntu1.1 |
kinetic | DNE | |
lunar | DNE | |
trusty | DNE | |
upstream | needs-triage |
Показывать по
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
Acceptance of some invalid Transfer-Encoding headers in the HTTP/1 client in net/http before Go 1.17.12 and Go 1.18.4 allows HTTP request smuggling if combined with an intermediate server that also improperly fails to reject the header as invalid.
Acceptance of some invalid Transfer-Encoding headers in the HTTP/1 client in net/http before Go 1.17.12 and Go 1.18.4 allows HTTP request smuggling if combined with an intermediate server that also improperly fails to reject the header as invalid.
Acceptance of some invalid Transfer-Encoding headers in the HTTP/1 cli ...
Acceptance of some invalid Transfer-Encoding headers in the HTTP/1 client in net/http before Go 1.17.12 and Go 1.18.4 allows HTTP request smuggling if combined with an intermediate server that also improperly fails to reject the header as invalid.
EPSS
6.5 Medium
CVSS3