Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 127

Количество 127

fstec логотип

BDU:2024-02688

больше 2 лет назад

Уязвимость библиотек net/http и net/http2 языка программирования Go, связана с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.3
EPSS: Критический
ubuntu логотип

CVE-2023-45289

больше 2 лет назад

When following an HTTP redirect to a domain which is not a subdomain match or exact match of the initial domain, an http.Client does not forward sensitive headers such as "Authorization" or "Cookie". For example, a redirect from foo.com to www.foo.com will forward the Authorization header, but a redirect to bar.com will not. A maliciously crafted HTTP redirect could cause sensitive headers to be unexpectedly forwarded.

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2023-45289

больше 2 лет назад

When following an HTTP redirect to a domain which is not a subdomain match or exact match of the initial domain, an http.Client does not forward sensitive headers such as "Authorization" or "Cookie". For example, a redirect from foo.com to www.foo.com will forward the Authorization header, but a redirect to bar.com will not. A maliciously crafted HTTP redirect could cause sensitive headers to be unexpectedly forwarded.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2023-45289

больше 2 лет назад

When following an HTTP redirect to a domain which is not a subdomain match or exact match of the initial domain, an http.Client does not forward sensitive headers such as "Authorization" or "Cookie". For example, a redirect from foo.com to www.foo.com will forward the Authorization header, but a redirect to bar.com will not. A maliciously crafted HTTP redirect could cause sensitive headers to be unexpectedly forwarded.

CVSS3: 4.3
EPSS: Низкий
msrc логотип

CVE-2023-45289

около 1 года назад

Incorrect forwarding of sensitive headers and cookies on HTTP redirect in net/http

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2023-45289

больше 2 лет назад

When following an HTTP redirect to a domain which is not a subdomain m ...

CVSS3: 4.3
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20815-1

4 месяца назад

Security update for google-osconfig-agent

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20609-1

5 месяцев назад

Security update for google-guest-agent

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0813-1

больше 1 года назад

Security update for buildah

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0458-1

больше 1 года назад

Security update for podman

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0420-1

больше 1 года назад

Security update for skopeo

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0313-1

больше 1 года назад

Security update for apptainer

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:01992-1

больше 1 года назад

Security update for golang-github-prometheus-alertmanager

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:01990-1

больше 1 года назад

Security update for golang-github-prometheus-prometheus

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:01988-1

больше 1 года назад

Security update for golang-github-prometheus-node_exporter

EPSS: Низкий
redos логотип

ROS-20240923-06

около 2 лет назад

Уязвимость consul

CVSS3: 5.3
EPSS: Критический
redos логотип

ROS-20240422-11

около 2 лет назад

Уязвимость terraform

CVSS3: 5.3
EPSS: Критический
altlinux логотип

ALT-PU-2024-5073

больше 2 лет назад

ALT-PU-2024-5073: package `golang` update to version 1.21.9-alt1

CVSS3: 7.5
EPSS: Критический
altlinux логотип

ALT-PU-2024-5071

больше 2 лет назад

ALT-PU-2024-5071: package `golang` update to version 1.22.2-alt1

CVSS3: 7.5
EPSS: Критический
suse-cvrf логотип

openSUSE-SU-2026:21136-1

3 месяца назад

Security update for golang-github-prometheus-alertmanager

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2024-02688

Уязвимость библиотек net/http и net/http2 языка программирования Go, связана с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.3
92%
Критический
больше 2 лет назад
ubuntu логотип
CVE-2023-45289

When following an HTTP redirect to a domain which is not a subdomain match or exact match of the initial domain, an http.Client does not forward sensitive headers such as "Authorization" or "Cookie". For example, a redirect from foo.com to www.foo.com will forward the Authorization header, but a redirect to bar.com will not. A maliciously crafted HTTP redirect could cause sensitive headers to be unexpectedly forwarded.

CVSS3: 4.3
1%
Низкий
больше 2 лет назад
redhat логотип
CVE-2023-45289

When following an HTTP redirect to a domain which is not a subdomain match or exact match of the initial domain, an http.Client does not forward sensitive headers such as "Authorization" or "Cookie". For example, a redirect from foo.com to www.foo.com will forward the Authorization header, but a redirect to bar.com will not. A maliciously crafted HTTP redirect could cause sensitive headers to be unexpectedly forwarded.

CVSS3: 5.3
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-45289

When following an HTTP redirect to a domain which is not a subdomain match or exact match of the initial domain, an http.Client does not forward sensitive headers such as "Authorization" or "Cookie". For example, a redirect from foo.com to www.foo.com will forward the Authorization header, but a redirect to bar.com will not. A maliciously crafted HTTP redirect could cause sensitive headers to be unexpectedly forwarded.

CVSS3: 4.3
1%
Низкий
больше 2 лет назад
msrc логотип
CVE-2023-45289

Incorrect forwarding of sensitive headers and cookies on HTTP redirect in net/http

CVSS3: 4.3
1%
Низкий
около 1 года назад
debian логотип
CVE-2023-45289

When following an HTTP redirect to a domain which is not a subdomain m ...

CVSS3: 4.3
1%
Низкий
больше 2 лет назад
suse-cvrf логотип
openSUSE-SU-2026:20815-1

Security update for google-osconfig-agent

4 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20609-1

Security update for google-guest-agent

5 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:0813-1

Security update for buildah

больше 1 года назад
suse-cvrf логотип
SUSE-SU-2025:0458-1

Security update for podman

больше 1 года назад
suse-cvrf логотип
SUSE-SU-2025:0420-1

Security update for skopeo

больше 1 года назад
suse-cvrf логотип
SUSE-SU-2025:0313-1

Security update for apptainer

больше 1 года назад
suse-cvrf логотип
SUSE-SU-2025:01992-1

Security update for golang-github-prometheus-alertmanager

больше 1 года назад
suse-cvrf логотип
SUSE-SU-2025:01990-1

Security update for golang-github-prometheus-prometheus

больше 1 года назад
suse-cvrf логотип
SUSE-SU-2025:01988-1

Security update for golang-github-prometheus-node_exporter

больше 1 года назад
redos логотип
ROS-20240923-06

Уязвимость consul

CVSS3: 5.3
92%
Критический
около 2 лет назад
redos логотип
ROS-20240422-11

Уязвимость terraform

CVSS3: 5.3
92%
Критический
около 2 лет назад
altlinux логотип
ALT-PU-2024-5073

ALT-PU-2024-5073: package `golang` update to version 1.21.9-alt1

CVSS3: 7.5
92%
Критический
больше 2 лет назад
altlinux логотип
ALT-PU-2024-5071

ALT-PU-2024-5071: package `golang` update to version 1.22.2-alt1

CVSS3: 7.5
92%
Критический
больше 2 лет назад
suse-cvrf логотип
openSUSE-SU-2026:21136-1

Security update for golang-github-prometheus-alertmanager

3 месяца назад

Уязвимостей на страницу