Описание
Improper exposure of client IP addresses in net/http before Go 1.17.12 and Go 1.18.4 can be triggered by calling httputil.ReverseProxy.ServeHTTP with a Request.Header map containing a nil value for the X-Forwarded-For header, which causes ReverseProxy to set the client IP as the value of the X-Forwarded-For header.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | ignored | end of standard support |
| devel | DNE | |
| esm-apps/bionic | released | 1.13.8-1ubuntu1~18.04.4+esm1 |
| esm-apps/jammy | released | 1.13.8-1ubuntu2.22.04.2 |
| esm-apps/xenial | released | 1.13.8-1ubuntu1~16.04.3+esm3 |
| esm-infra/focal | released | 1.13.8-1ubuntu1.2 |
| focal | released | 1.13.8-1ubuntu1.2 |
| jammy | released | 1.13.8-1ubuntu2.22.04.2 |
| lunar | DNE | |
| mantic | DNE |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | ignored | end of standard support |
| devel | DNE | |
| esm-apps/bionic | released | 1.16.2-0ubuntu1~18.04.2+esm1 |
| esm-apps/focal | released | 1.16.2-0ubuntu1~20.04.1 |
| focal | released | 1.16.2-0ubuntu1~20.04.1 |
| jammy | DNE | |
| lunar | DNE | |
| mantic | DNE | |
| trusty | ignored | end of standard support |
| upstream | needs-triage |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | released | 1.18.1-1ubuntu1~18.04.4 |
| devel | DNE | |
| focal | released | 1.18.1-1ubuntu1~20.04.2 |
| impish | DNE | |
| jammy | released | 1.18.1-1ubuntu1.1 |
| kinetic | DNE | |
| lunar | DNE | |
| trusty | DNE | |
| upstream | needs-triage | |
| xenial | DNE |
Показывать по
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
Improper exposure of client IP addresses in net/http before Go 1.17.12 and Go 1.18.4 can be triggered by calling httputil.ReverseProxy.ServeHTTP with a Request.Header map containing a nil value for the X-Forwarded-For header, which causes ReverseProxy to set the client IP as the value of the X-Forwarded-For header.
Improper exposure of client IP addresses in net/http before Go 1.17.12 and Go 1.18.4 can be triggered by calling httputil.ReverseProxy.ServeHTTP with a Request.Header map containing a nil value for the X-Forwarded-For header, which causes ReverseProxy to set the client IP as the value of the X-Forwarded-For header.
Improper exposure of client IP addresses in net/http before Go 1.17.12 ...
Improper exposure of client IP addresses in net/http before Go 1.17.12 and Go 1.18.4 can be triggered by calling httputil.ReverseProxy.ServeHTTP with a Request.Header map containing a nil value for the X-Forwarded-For header, which causes ReverseProxy to set the client IP as the value of the X-Forwarded-For header.
EPSS
6.5 Medium
CVSS3