Количество 42
Количество 42
ELSA-2024-1131
ELSA-2024-1131: golang security update (MODERATE)
ELSA-2024-0887
ELSA-2024-0887: go-toolset:ol8 security update (MODERATE)
SUSE-SU-2023:4931-1
Security update for go1.21-openssl
SUSE-SU-2023:4930-1
Security update for go1.20-openssl
SUSE-SU-2023:4709-1
Security update for go1.21
SUSE-SU-2023:4708-1
Security update for go1.20
ROS-20240402-17
Множественные уязвимости golang
ALT-PU-2023-7813
ALT-PU-2023-7813: package `golang` update to version 1.21.5-alt1
ALT-PU-2023-7811
ALT-PU-2023-7811: package `golang` update to version 1.20.12-alt1
ALT-PU-2023-8672
ALT-PU-2023-8672: package `golang` update to version 1.21.0-alt1
ROS-20240805-03
Множественные уязвимости consul
CVE-2023-45285
Using go get to fetch a module with the ".git" suffix may unexpectedly fallback to the insecure "git://" protocol if the module is unavailable via the secure "https://" and "git+ssh://" protocols, even if GOINSECURE is not set for said module. This only affects users who are not using the module proxy and are fetching modules directly (i.e. GOPROXY=off).
CVE-2023-45285
Using go get to fetch a module with the ".git" suffix may unexpectedly fallback to the insecure "git://" protocol if the module is unavailable via the secure "https://" and "git+ssh://" protocols, even if GOINSECURE is not set for said module. This only affects users who are not using the module proxy and are fetching modules directly (i.e. GOPROXY=off).
CVE-2023-45285
Using go get to fetch a module with the ".git" suffix may unexpectedly fallback to the insecure "git://" protocol if the module is unavailable via the secure "https://" and "git+ssh://" protocols, even if GOINSECURE is not set for said module. This only affects users who are not using the module proxy and are fetching modules directly (i.e. GOPROXY=off).
CVE-2023-45285
Command 'go get' may unexpectedly fallback to insecure git in cmd/go
CVE-2023-45285
Using go get to fetch a module with the ".git" suffix may unexpectedly ...
CVE-2023-39326
A malicious HTTP sender can use chunk extensions to cause a receiver reading from a request or response body to read many more bytes from the network than are in the body. A malicious HTTP client can further exploit this to cause a server to automatically read a large amount of data (up to about 1GiB) when a handler fails to read the entire body of a request. Chunk extensions are a little-used HTTP feature which permit including additional metadata in a request or response body sent using the chunked encoding. The net/http chunked encoding reader discards this metadata. A sender can exploit this by inserting a large metadata segment with each byte transferred. The chunk reader now produces an error if the ratio of real body to encoded bytes grows too small.
CVE-2023-39326
A malicious HTTP sender can use chunk extensions to cause a receiver reading from a request or response body to read many more bytes from the network than are in the body. A malicious HTTP client can further exploit this to cause a server to automatically read a large amount of data (up to about 1GiB) when a handler fails to read the entire body of a request. Chunk extensions are a little-used HTTP feature which permit including additional metadata in a request or response body sent using the chunked encoding. The net/http chunked encoding reader discards this metadata. A sender can exploit this by inserting a large metadata segment with each byte transferred. The chunk reader now produces an error if the ratio of real body to encoded bytes grows too small.
CVE-2023-39326
A malicious HTTP sender can use chunk extensions to cause a receiver reading from a request or response body to read many more bytes from the network than are in the body. A malicious HTTP client can further exploit this to cause a server to automatically read a large amount of data (up to about 1GiB) when a handler fails to read the entire body of a request. Chunk extensions are a little-used HTTP feature which permit including additional metadata in a request or response body sent using the chunked encoding. The net/http chunked encoding reader discards this metadata. A sender can exploit this by inserting a large metadata segment with each byte transferred. The chunk reader now produces an error if the ratio of real body to encoded bytes grows too small.
CVE-2023-39326
Denial of service via chunk extensions in net/http
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
ELSA-2024-1131 ELSA-2024-1131: golang security update (MODERATE) | больше 2 лет назад | |||
ELSA-2024-0887 ELSA-2024-0887: go-toolset:ol8 security update (MODERATE) | больше 2 лет назад | |||
SUSE-SU-2023:4931-1 Security update for go1.21-openssl | почти 3 года назад | |||
SUSE-SU-2023:4930-1 Security update for go1.20-openssl | почти 3 года назад | |||
SUSE-SU-2023:4709-1 Security update for go1.21 | почти 3 года назад | |||
SUSE-SU-2023:4708-1 Security update for go1.20 | почти 3 года назад | |||
ROS-20240402-17 Множественные уязвимости golang | CVSS3: 7.5 | больше 2 лет назад | ||
ALT-PU-2023-7813 ALT-PU-2023-7813: package `golang` update to version 1.21.5-alt1 | CVSS3: 7.5 | почти 3 года назад | ||
ALT-PU-2023-7811 ALT-PU-2023-7811: package `golang` update to version 1.20.12-alt1 | CVSS3: 7.5 | почти 3 года назад | ||
ALT-PU-2023-8672 ALT-PU-2023-8672: package `golang` update to version 1.21.0-alt1 | CVSS3: 7.5 | около 3 лет назад | ||
ROS-20240805-03 Множественные уязвимости consul | CVSS3: 7.5 | около 2 лет назад | ||
CVE-2023-45285 Using go get to fetch a module with the ".git" suffix may unexpectedly fallback to the insecure "git://" protocol if the module is unavailable via the secure "https://" and "git+ssh://" protocols, even if GOINSECURE is not set for said module. This only affects users who are not using the module proxy and are fetching modules directly (i.e. GOPROXY=off). | CVSS3: 7.5 | 1% Низкий | почти 3 года назад | |
CVE-2023-45285 Using go get to fetch a module with the ".git" suffix may unexpectedly fallback to the insecure "git://" protocol if the module is unavailable via the secure "https://" and "git+ssh://" protocols, even if GOINSECURE is not set for said module. This only affects users who are not using the module proxy and are fetching modules directly (i.e. GOPROXY=off). | CVSS3: 7.5 | 1% Низкий | почти 3 года назад | |
CVE-2023-45285 Using go get to fetch a module with the ".git" suffix may unexpectedly fallback to the insecure "git://" protocol if the module is unavailable via the secure "https://" and "git+ssh://" protocols, even if GOINSECURE is not set for said module. This only affects users who are not using the module proxy and are fetching modules directly (i.e. GOPROXY=off). | CVSS3: 7.5 | 1% Низкий | почти 3 года назад | |
CVE-2023-45285 Command 'go get' may unexpectedly fallback to insecure git in cmd/go | CVSS3: 7.5 | 1% Низкий | 21 день назад | |
CVE-2023-45285 Using go get to fetch a module with the ".git" suffix may unexpectedly ... | CVSS3: 7.5 | 1% Низкий | почти 3 года назад | |
CVE-2023-39326 A malicious HTTP sender can use chunk extensions to cause a receiver reading from a request or response body to read many more bytes from the network than are in the body. A malicious HTTP client can further exploit this to cause a server to automatically read a large amount of data (up to about 1GiB) when a handler fails to read the entire body of a request. Chunk extensions are a little-used HTTP feature which permit including additional metadata in a request or response body sent using the chunked encoding. The net/http chunked encoding reader discards this metadata. A sender can exploit this by inserting a large metadata segment with each byte transferred. The chunk reader now produces an error if the ratio of real body to encoded bytes grows too small. | CVSS3: 5.3 | 1% Низкий | почти 3 года назад | |
CVE-2023-39326 A malicious HTTP sender can use chunk extensions to cause a receiver reading from a request or response body to read many more bytes from the network than are in the body. A malicious HTTP client can further exploit this to cause a server to automatically read a large amount of data (up to about 1GiB) when a handler fails to read the entire body of a request. Chunk extensions are a little-used HTTP feature which permit including additional metadata in a request or response body sent using the chunked encoding. The net/http chunked encoding reader discards this metadata. A sender can exploit this by inserting a large metadata segment with each byte transferred. The chunk reader now produces an error if the ratio of real body to encoded bytes grows too small. | CVSS3: 5.3 | 1% Низкий | почти 3 года назад | |
CVE-2023-39326 A malicious HTTP sender can use chunk extensions to cause a receiver reading from a request or response body to read many more bytes from the network than are in the body. A malicious HTTP client can further exploit this to cause a server to automatically read a large amount of data (up to about 1GiB) when a handler fails to read the entire body of a request. Chunk extensions are a little-used HTTP feature which permit including additional metadata in a request or response body sent using the chunked encoding. The net/http chunked encoding reader discards this metadata. A sender can exploit this by inserting a large metadata segment with each byte transferred. The chunk reader now produces an error if the ratio of real body to encoded bytes grows too small. | CVSS3: 5.3 | 1% Низкий | почти 3 года назад | |
CVE-2023-39326 Denial of service via chunk extensions in net/http | CVSS3: 5.3 | 1% Низкий | около 1 года назад |
Уязвимостей на страницу