CVE-2019-16276
Public on 2019-09-30
Modified on 2020-01-17
Description
It was discovered that net/http (through net/textproto) in golang does not correctly interpret HTTP requests where an HTTP header contains spaces before the colon. This could be abused by an attacker to smuggle HTTP requests when a proxy or a firewall is placed behind a server implemented in Go or to filter bypasses depending on the specific network configuration.
Severity
CVSS v3 Base Score
See breakdown
Affected Packages
Platform | Package | Release Date | Advisory | Status |
---|---|---|---|---|
Amazon Linux 1 | golang | 2019-11-19 | ALAS-2019-1321 | Fixed |
Amazon Linux 1 | golang | 2020-01-14 | ALAS-2020-1336 | Fixed |
Amazon Linux 2 - Core | golang | 2019-10-21 | ALAS2-2019-1335 | Fixed |
Amazon Linux 2 - Core | golang | 2020-01-14 | ALAS2-2020-1383 | Fixed |
Amazon Linux 2 - Core | golang | 2024-05-09 | ALAS2-2024-2545 | Fixed |
CVSS Scores
Score Type | Score | Vector | |
---|---|---|---|
Amazon Linux | CVSSv3 | 6.5 | CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
NVD | CVSSv2 | 5.0 | AV:N/AC:L/Au:N/C:N/I:P/A:N |
NVD | CVSSv3 | 7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |