Количество 127
Количество 127
BDU:2024-02688
Уязвимость библиотек net/http и net/http2 языка программирования Go, связана с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании
CVE-2023-45289
When following an HTTP redirect to a domain which is not a subdomain match or exact match of the initial domain, an http.Client does not forward sensitive headers such as "Authorization" or "Cookie". For example, a redirect from foo.com to www.foo.com will forward the Authorization header, but a redirect to bar.com will not. A maliciously crafted HTTP redirect could cause sensitive headers to be unexpectedly forwarded.
CVE-2023-45289
When following an HTTP redirect to a domain which is not a subdomain match or exact match of the initial domain, an http.Client does not forward sensitive headers such as "Authorization" or "Cookie". For example, a redirect from foo.com to www.foo.com will forward the Authorization header, but a redirect to bar.com will not. A maliciously crafted HTTP redirect could cause sensitive headers to be unexpectedly forwarded.
CVE-2023-45289
When following an HTTP redirect to a domain which is not a subdomain match or exact match of the initial domain, an http.Client does not forward sensitive headers such as "Authorization" or "Cookie". For example, a redirect from foo.com to www.foo.com will forward the Authorization header, but a redirect to bar.com will not. A maliciously crafted HTTP redirect could cause sensitive headers to be unexpectedly forwarded.
CVE-2023-45289
Incorrect forwarding of sensitive headers and cookies on HTTP redirect in net/http
CVE-2023-45289
When following an HTTP redirect to a domain which is not a subdomain m ...
openSUSE-SU-2026:20815-1
Security update for google-osconfig-agent
openSUSE-SU-2026:20609-1
Security update for google-guest-agent
SUSE-SU-2025:0813-1
Security update for buildah
SUSE-SU-2025:0458-1
Security update for podman
SUSE-SU-2025:0420-1
Security update for skopeo
SUSE-SU-2025:0313-1
Security update for apptainer
SUSE-SU-2025:01992-1
Security update for golang-github-prometheus-alertmanager
SUSE-SU-2025:01990-1
Security update for golang-github-prometheus-prometheus
SUSE-SU-2025:01988-1
Security update for golang-github-prometheus-node_exporter
ROS-20240923-06
Уязвимость consul
ROS-20240422-11
Уязвимость terraform
ALT-PU-2024-5073
ALT-PU-2024-5073: package `golang` update to version 1.21.9-alt1
ALT-PU-2024-5071
ALT-PU-2024-5071: package `golang` update to version 1.22.2-alt1
openSUSE-SU-2026:21136-1
Security update for golang-github-prometheus-alertmanager
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2024-02688 Уязвимость библиотек net/http и net/http2 языка программирования Go, связана с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 5.3 | 92% Критический | больше 2 лет назад | |
CVE-2023-45289 When following an HTTP redirect to a domain which is not a subdomain match or exact match of the initial domain, an http.Client does not forward sensitive headers such as "Authorization" or "Cookie". For example, a redirect from foo.com to www.foo.com will forward the Authorization header, but a redirect to bar.com will not. A maliciously crafted HTTP redirect could cause sensitive headers to be unexpectedly forwarded. | CVSS3: 4.3 | 1% Низкий | больше 2 лет назад | |
CVE-2023-45289 When following an HTTP redirect to a domain which is not a subdomain match or exact match of the initial domain, an http.Client does not forward sensitive headers such as "Authorization" or "Cookie". For example, a redirect from foo.com to www.foo.com will forward the Authorization header, but a redirect to bar.com will not. A maliciously crafted HTTP redirect could cause sensitive headers to be unexpectedly forwarded. | CVSS3: 5.3 | 1% Низкий | больше 2 лет назад | |
CVE-2023-45289 When following an HTTP redirect to a domain which is not a subdomain match or exact match of the initial domain, an http.Client does not forward sensitive headers such as "Authorization" or "Cookie". For example, a redirect from foo.com to www.foo.com will forward the Authorization header, but a redirect to bar.com will not. A maliciously crafted HTTP redirect could cause sensitive headers to be unexpectedly forwarded. | CVSS3: 4.3 | 1% Низкий | больше 2 лет назад | |
CVE-2023-45289 Incorrect forwarding of sensitive headers and cookies on HTTP redirect in net/http | CVSS3: 4.3 | 1% Низкий | около 1 года назад | |
CVE-2023-45289 When following an HTTP redirect to a domain which is not a subdomain m ... | CVSS3: 4.3 | 1% Низкий | больше 2 лет назад | |
openSUSE-SU-2026:20815-1 Security update for google-osconfig-agent | 4 месяца назад | |||
openSUSE-SU-2026:20609-1 Security update for google-guest-agent | 5 месяцев назад | |||
SUSE-SU-2025:0813-1 Security update for buildah | больше 1 года назад | |||
SUSE-SU-2025:0458-1 Security update for podman | больше 1 года назад | |||
SUSE-SU-2025:0420-1 Security update for skopeo | больше 1 года назад | |||
SUSE-SU-2025:0313-1 Security update for apptainer | больше 1 года назад | |||
SUSE-SU-2025:01992-1 Security update for golang-github-prometheus-alertmanager | больше 1 года назад | |||
SUSE-SU-2025:01990-1 Security update for golang-github-prometheus-prometheus | больше 1 года назад | |||
SUSE-SU-2025:01988-1 Security update for golang-github-prometheus-node_exporter | больше 1 года назад | |||
ROS-20240923-06 Уязвимость consul | CVSS3: 5.3 | 92% Критический | около 2 лет назад | |
ROS-20240422-11 Уязвимость terraform | CVSS3: 5.3 | 92% Критический | около 2 лет назад | |
ALT-PU-2024-5073 ALT-PU-2024-5073: package `golang` update to version 1.21.9-alt1 | CVSS3: 7.5 | 92% Критический | больше 2 лет назад | |
ALT-PU-2024-5071 ALT-PU-2024-5071: package `golang` update to version 1.22.2-alt1 | CVSS3: 7.5 | 92% Критический | больше 2 лет назад | |
openSUSE-SU-2026:21136-1 Security update for golang-github-prometheus-alertmanager | 3 месяца назад |
Уязвимостей на страницу