CVE-2019-16276
golang-1.11 - security update
EPSS 5.2%
描述
net/http (through net/textproto) used to accept and normalize invalid HTTP/1.1 headers with a space before the colon, in violation of RFC 7230. If a Go server is used behind an uncommon reverse proxy that accepts and forwards but doesn't normalize such invalid headers, the reverse proxy and the server can interpret the headers differently. This can lead to filter bypasses or request smuggling, the latter if requests from separate clients are multiplexed onto the same upstream connection by the proxy. Such invalid headers are now rejected by Go servers, and passed without normalization to Go client applications.
如何修補 CVE-2019-16276
要修補 CVE-2019-16276,請將受影響套件升級到下列已修補版本。
- —升級至 1.11.6-1+deb10u2 或更新版本
- —升級至 1.12.10 或更新版本
CVE-2019-16276 正在被利用嗎?
中等 — EPSS 為 5.2%,可持續追蹤但非最高優先。
受影響套件(2)
- from 0, < 1.11.6-1+deb10u2
- from 0, < 1.12.10, >= 1.13.0-0, < 1.13.1