Количество 28
Количество 28
BDU:2024-02034
Уязвимость пакета golang операционной системы Debian GNU/Linux, позволяющая нарушителю получить доступ к конфиденциальной информации
ALT-PU-2024-3506
ALT-PU-2024-3506: package `golang` update to version 1.22.1-alt1
ALT-PU-2024-3504
ALT-PU-2024-3504: package `golang` update to version 1.21.8-alt1
ROS-20240422-05
Множественные уязвимости golang
ROS-20240805-08
Множественные уязвимости consul
ALT-PU-2024-11781
ALT-PU-2024-11781: package `golang` update to version 1.22.6-alt1
CVE-2023-45289
When following an HTTP redirect to a domain which is not a subdomain match or exact match of the initial domain, an http.Client does not forward sensitive headers such as "Authorization" or "Cookie". For example, a redirect from foo.com to www.foo.com will forward the Authorization header, but a redirect to bar.com will not. A maliciously crafted HTTP redirect could cause sensitive headers to be unexpectedly forwarded.
CVE-2023-45289
When following an HTTP redirect to a domain which is not a subdomain match or exact match of the initial domain, an http.Client does not forward sensitive headers such as "Authorization" or "Cookie". For example, a redirect from foo.com to www.foo.com will forward the Authorization header, but a redirect to bar.com will not. A maliciously crafted HTTP redirect could cause sensitive headers to be unexpectedly forwarded.
CVE-2023-45289
When following an HTTP redirect to a domain which is not a subdomain match or exact match of the initial domain, an http.Client does not forward sensitive headers such as "Authorization" or "Cookie". For example, a redirect from foo.com to www.foo.com will forward the Authorization header, but a redirect to bar.com will not. A maliciously crafted HTTP redirect could cause sensitive headers to be unexpectedly forwarded.
CVE-2023-45289
Incorrect forwarding of sensitive headers and cookies on HTTP redirect in net/http
CVE-2023-45289
When following an HTTP redirect to a domain which is not a subdomain m ...
GHSA-32ch-6x54-q4h9
When following an HTTP redirect to a domain which is not a subdomain match or exact match of the initial domain, an http.Client does not forward sensitive headers such as "Authorization" or "Cookie". For example, a redirect from foo.com to www.foo.com will forward the Authorization header, but a redirect to bar.com will not. A maliciously crafted HTTP redirect could cause sensitive headers to be unexpectedly forwarded.
RLSA-2024:3346
Important: git-lfs security update
RLSA-2024:2724
Important: git-lfs security update
ELSA-2024-3346
ELSA-2024-3346: git-lfs security update (IMPORTANT)
ELSA-2024-2724
ELSA-2024-2724: git-lfs security update (IMPORTANT)
SUSE-SU-2024:0936-1
Security update for go1.22
SUSE-SU-2024:0812-1
Security update for go1.22
SUSE-SU-2024:0811-1
Security update for go1.21
SUSE-SU-2024:0800-1
Security update for go1.21
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2024-02034 Уязвимость пакета golang операционной системы Debian GNU/Linux, позволяющая нарушителю получить доступ к конфиденциальной информации | CVSS3: 3.1 | 1% Низкий | больше 2 лет назад | |
ALT-PU-2024-3506 ALT-PU-2024-3506: package `golang` update to version 1.22.1-alt1 | CVSS3: 7.5 | больше 2 лет назад | ||
ALT-PU-2024-3504 ALT-PU-2024-3504: package `golang` update to version 1.21.8-alt1 | CVSS3: 7.5 | больше 2 лет назад | ||
ROS-20240422-05 Множественные уязвимости golang | CVSS3: 7.5 | больше 2 лет назад | ||
ROS-20240805-08 Множественные уязвимости consul | CVSS3: 7.5 | около 2 лет назад | ||
ALT-PU-2024-11781 ALT-PU-2024-11781: package `golang` update to version 1.22.6-alt1 | CVSS3: 9.8 | около 2 лет назад | ||
CVE-2023-45289 When following an HTTP redirect to a domain which is not a subdomain match or exact match of the initial domain, an http.Client does not forward sensitive headers such as "Authorization" or "Cookie". For example, a redirect from foo.com to www.foo.com will forward the Authorization header, but a redirect to bar.com will not. A maliciously crafted HTTP redirect could cause sensitive headers to be unexpectedly forwarded. | CVSS3: 4.3 | 1% Низкий | больше 2 лет назад | |
CVE-2023-45289 When following an HTTP redirect to a domain which is not a subdomain match or exact match of the initial domain, an http.Client does not forward sensitive headers such as "Authorization" or "Cookie". For example, a redirect from foo.com to www.foo.com will forward the Authorization header, but a redirect to bar.com will not. A maliciously crafted HTTP redirect could cause sensitive headers to be unexpectedly forwarded. | CVSS3: 5.3 | 1% Низкий | больше 2 лет назад | |
CVE-2023-45289 When following an HTTP redirect to a domain which is not a subdomain match or exact match of the initial domain, an http.Client does not forward sensitive headers such as "Authorization" or "Cookie". For example, a redirect from foo.com to www.foo.com will forward the Authorization header, but a redirect to bar.com will not. A maliciously crafted HTTP redirect could cause sensitive headers to be unexpectedly forwarded. | CVSS3: 4.3 | 1% Низкий | больше 2 лет назад | |
CVE-2023-45289 Incorrect forwarding of sensitive headers and cookies on HTTP redirect in net/http | CVSS3: 4.3 | 1% Низкий | около 1 года назад | |
CVE-2023-45289 When following an HTTP redirect to a domain which is not a subdomain m ... | CVSS3: 4.3 | 1% Низкий | больше 2 лет назад | |
GHSA-32ch-6x54-q4h9 When following an HTTP redirect to a domain which is not a subdomain match or exact match of the initial domain, an http.Client does not forward sensitive headers such as "Authorization" or "Cookie". For example, a redirect from foo.com to www.foo.com will forward the Authorization header, but a redirect to bar.com will not. A maliciously crafted HTTP redirect could cause sensitive headers to be unexpectedly forwarded. | CVSS3: 4.3 | 1% Низкий | больше 2 лет назад | |
RLSA-2024:3346 Important: git-lfs security update | больше 2 лет назад | |||
RLSA-2024:2724 Important: git-lfs security update | больше 2 лет назад | |||
ELSA-2024-3346 ELSA-2024-3346: git-lfs security update (IMPORTANT) | больше 2 лет назад | |||
ELSA-2024-2724 ELSA-2024-2724: git-lfs security update (IMPORTANT) | больше 2 лет назад | |||
SUSE-SU-2024:0936-1 Security update for go1.22 | больше 2 лет назад | |||
SUSE-SU-2024:0812-1 Security update for go1.22 | больше 2 лет назад | |||
SUSE-SU-2024:0811-1 Security update for go1.21 | больше 2 лет назад | |||
SUSE-SU-2024:0800-1 Security update for go1.21 | больше 2 лет назад |
Уязвимостей на страницу