Количество 98
Количество 98
CVE-2023-45288
An attacker may cause an HTTP/2 endpoint to read arbitrary amounts of ...

ROS-20240805-08
Множественные уязвимости consul

SUSE-SU-2025:0581-1
Security update for buildah

SUSE-SU-2025:0299-1
Security update for ignition

SUSE-SU-2024:3155-1
Security update for kubernetes1.26

SUSE-SU-2024:2108-1
Security update for containerd

SUSE-SU-2024:1161-1
Security update for go1.21

SUSE-SU-2024:1160-1
Security update for go1.22

SUSE-SU-2024:1122-1
Security update for go1.21

SUSE-SU-2024:1121-1
Security update for go1.22

RLSA-2024:2699
Important: git-lfs security update
GHSA-4v7x-pqxf-cx7m
net/http, x/net/http2: close connections when receiving too many headers
ELSA-2024-2699
ELSA-2024-2699: git-lfs security update (IMPORTANT)
ELSA-2024-1963
ELSA-2024-1963: golang security update (IMPORTANT)
ELSA-2024-1962
ELSA-2024-1962: go-toolset:ol8 security update (IMPORTANT)

BDU:2024-02688
Уязвимость библиотек net/http и net/http2 языка программирования Go, связана с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVE-2023-45289
When following an HTTP redirect to a domain which is not a subdomain match or exact match of the initial domain, an http.Client does not forward sensitive headers such as "Authorization" or "Cookie". For example, a redirect from foo.com to www.foo.com will forward the Authorization header, but a redirect to bar.com will not. A maliciously crafted HTTP redirect could cause sensitive headers to be unexpectedly forwarded.

CVE-2023-45289
When following an HTTP redirect to a domain which is not a subdomain match or exact match of the initial domain, an http.Client does not forward sensitive headers such as "Authorization" or "Cookie". For example, a redirect from foo.com to www.foo.com will forward the Authorization header, but a redirect to bar.com will not. A maliciously crafted HTTP redirect could cause sensitive headers to be unexpectedly forwarded.

CVE-2023-45289
When following an HTTP redirect to a domain which is not a subdomain match or exact match of the initial domain, an http.Client does not forward sensitive headers such as "Authorization" or "Cookie". For example, a redirect from foo.com to www.foo.com will forward the Authorization header, but a redirect to bar.com will not. A maliciously crafted HTTP redirect could cause sensitive headers to be unexpectedly forwarded.

CVE-2023-45289
Incorrect forwarding of sensitive headers and cookies on HTTP redirect in net/http
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
CVE-2023-45288 An attacker may cause an HTTP/2 endpoint to read arbitrary amounts of ... | CVSS3: 7.5 | 67% Средний | больше 1 года назад | |
![]() | ROS-20240805-08 Множественные уязвимости consul | CVSS3: 7.5 | около 1 года назад | |
![]() | SUSE-SU-2025:0581-1 Security update for buildah | 67% Средний | 8 месяцев назад | |
![]() | SUSE-SU-2025:0299-1 Security update for ignition | 67% Средний | 9 месяцев назад | |
![]() | SUSE-SU-2024:3155-1 Security update for kubernetes1.26 | 67% Средний | около 1 года назад | |
![]() | SUSE-SU-2024:2108-1 Security update for containerd | 67% Средний | больше 1 года назад | |
![]() | SUSE-SU-2024:1161-1 Security update for go1.21 | 67% Средний | больше 1 года назад | |
![]() | SUSE-SU-2024:1160-1 Security update for go1.22 | 67% Средний | больше 1 года назад | |
![]() | SUSE-SU-2024:1122-1 Security update for go1.21 | 67% Средний | больше 1 года назад | |
![]() | SUSE-SU-2024:1121-1 Security update for go1.22 | 67% Средний | больше 1 года назад | |
![]() | RLSA-2024:2699 Important: git-lfs security update | 67% Средний | больше 1 года назад | |
GHSA-4v7x-pqxf-cx7m net/http, x/net/http2: close connections when receiving too many headers | CVSS3: 5.3 | 67% Средний | больше 1 года назад | |
ELSA-2024-2699 ELSA-2024-2699: git-lfs security update (IMPORTANT) | больше 1 года назад | |||
ELSA-2024-1963 ELSA-2024-1963: golang security update (IMPORTANT) | больше 1 года назад | |||
ELSA-2024-1962 ELSA-2024-1962: go-toolset:ol8 security update (IMPORTANT) | больше 1 года назад | |||
![]() | BDU:2024-02688 Уязвимость библиотек net/http и net/http2 языка программирования Go, связана с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 5.3 | 67% Средний | больше 1 года назад |
![]() | CVE-2023-45289 When following an HTTP redirect to a domain which is not a subdomain match or exact match of the initial domain, an http.Client does not forward sensitive headers such as "Authorization" or "Cookie". For example, a redirect from foo.com to www.foo.com will forward the Authorization header, but a redirect to bar.com will not. A maliciously crafted HTTP redirect could cause sensitive headers to be unexpectedly forwarded. | CVSS3: 4.3 | 0% Низкий | больше 1 года назад |
![]() | CVE-2023-45289 When following an HTTP redirect to a domain which is not a subdomain match or exact match of the initial domain, an http.Client does not forward sensitive headers such as "Authorization" or "Cookie". For example, a redirect from foo.com to www.foo.com will forward the Authorization header, but a redirect to bar.com will not. A maliciously crafted HTTP redirect could cause sensitive headers to be unexpectedly forwarded. | CVSS3: 5.3 | 0% Низкий | больше 1 года назад |
![]() | CVE-2023-45289 When following an HTTP redirect to a domain which is not a subdomain match or exact match of the initial domain, an http.Client does not forward sensitive headers such as "Authorization" or "Cookie". For example, a redirect from foo.com to www.foo.com will forward the Authorization header, but a redirect to bar.com will not. A maliciously crafted HTTP redirect could cause sensitive headers to be unexpectedly forwarded. | CVSS3: 4.3 | 0% Низкий | больше 1 года назад |
![]() | CVE-2023-45289 Incorrect forwarding of sensitive headers and cookies on HTTP redirect in net/http | CVSS3: 4.3 | 0% Низкий | около 2 месяцев назад |
Уязвимостей на страницу