跳转到帖子

Red Hat OpenShift: CVE-2023-29406: golang: net/http: insufficient sanitization of Host header

recommended_posts

发布于
  • Members

Red Hat OpenShift: CVE-2023-29406: golang: net/http: insufficient sanitization of Host header

Severity
7
CVSS
(AV:N/AC:M/Au:N/C:N/I:C/A:N)
Published
07/11/2023
Created
11/17/2023
Added
11/16/2023
Modified
01/28/2025

Description

The HTTP/1 client does not fully validate the contents of the Host header. A maliciously crafted Host header can inject additional headers or entire requests. With fix, the HTTP/1 client now refuses to send requests containing an invalid Request.Host or Request.URL.Host value.

Solution(s)

  • linuxrpm-upgrade-openshift
  • linuxrpm-upgrade-openshift-clients

References

  • https://attackerkb.com/topics/cve-2023-29406
  • CVE - 2023-29406
  • RHSA-2023:5530
  • RHSA-2023:5541
  • RHSA-2023:5721
  • RHSA-2023:5738
  • RHSA-2023:5933
  • RHSA-2023:5935
  • RHSA-2023:5947
  • RHSA-2023:5965
  • RHSA-2023:5974
  • RHSA-2023:5976
  • RHSA-2023:6031
  • RHSA-2023:6085
  • RHSA-2023:6115
  • RHSA-2023:6161
  • RHSA-2023:6296
  • RHSA-2023:6298
  • RHSA-2023:6346
  • RHSA-2023:6363
  • RHSA-2023:6402
  • RHSA-2023:6473
  • RHSA-2023:6474
  • RHSA-2023:6818
  • RHSA-2023:6840
  • RHSA-2023:6938
  • RHSA-2023:6939
  • RHSA-2023:7202
  • RHSA-2024:0293
  • RHSA-2024:1027
  • RHSA-2024:1383
  • RHSA-2024:1570
View more
  • 查看数 700
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。
注意:你的帖子需要版主批准后才能看到。

游客
回帖…