[ALPINE:CVE-2023-45288] forgejo, rclone, go vulnerability

Severity High
Fixed Packages 39
CVEs 1

[From CVE-2023-45288] An attacker may cause an HTTP/2 endpoint to read arbitrary amounts of header data by sending an excessive number of CONTINUATION frames. Maintaining HPACK state requires parsing and processing all HEADERS and CONTINUATION frames on a connection. When a request's headers exceed MaxHeaderBytes, no memory is allocated to store the excess headers, but they are still parsed. This permits an attacker to cause an HTTP/2 endpoint to read arbitrary amounts of header data, all associated with a request which is going to be rejected. These headers can include Huffman-encoded data which is significantly more expensive for the receiver to decode than for an attacker to send. The fix sets a limit on the amount of excess header frames we will process before closing a connection.

Package Fixed Version
pkg:apk/alpine/rclone?arch=x86_64&distro=alpine-edge = 1.67.0-r0
pkg:apk/alpine/rclone?arch=x86&distro=alpine-edge = 1.67.0-r0
pkg:apk/alpine/rclone?arch=s390x&distro=alpine-edge = 1.67.0-r0
pkg:apk/alpine/rclone?arch=riscv64&distro=alpine-edge = 1.67.0-r0
pkg:apk/alpine/rclone?arch=ppc64le&distro=alpine-edge = 1.67.0-r0
pkg:apk/alpine/rclone?arch=armv7&distro=alpine-edge = 1.67.0-r0
pkg:apk/alpine/rclone?arch=armhf&distro=alpine-edge = 1.67.0-r0
pkg:apk/alpine/rclone?arch=aarch64&distro=alpine-edge = 1.67.0-r0
pkg:apk/alpine/go?arch=x86_64&distro=alpine-edge = 1.22.2-r0
pkg:apk/alpine/go?arch=x86_64&distro=alpine-3.20 = 1.22.2-r0
pkg:apk/alpine/go?arch=x86_64&distro=alpine-3.19 = 1.21.9-r0
pkg:apk/alpine/go?arch=x86&distro=alpine-edge = 1.22.2-r0
pkg:apk/alpine/go?arch=x86&distro=alpine-3.20 = 1.22.2-r0
pkg:apk/alpine/go?arch=x86&distro=alpine-3.19 = 1.21.9-r0
pkg:apk/alpine/go?arch=s390x&distro=alpine-edge = 1.22.2-r0
pkg:apk/alpine/go?arch=s390x&distro=alpine-3.20 = 1.22.2-r0
pkg:apk/alpine/go?arch=s390x&distro=alpine-3.19 = 1.21.9-r0
pkg:apk/alpine/go?arch=riscv64&distro=alpine-edge = 1.22.2-r0
pkg:apk/alpine/go?arch=riscv64&distro=alpine-3.20 = 1.22.2-r0
pkg:apk/alpine/go?arch=ppc64le&distro=alpine-edge = 1.22.2-r0
pkg:apk/alpine/go?arch=ppc64le&distro=alpine-3.20 = 1.22.2-r0
pkg:apk/alpine/go?arch=ppc64le&distro=alpine-3.19 = 1.21.9-r0
pkg:apk/alpine/go?arch=armv7&distro=alpine-edge = 1.22.2-r0
pkg:apk/alpine/go?arch=armv7&distro=alpine-3.20 = 1.22.2-r0
pkg:apk/alpine/go?arch=armv7&distro=alpine-3.19 = 1.21.9-r0
pkg:apk/alpine/go?arch=armhf&distro=alpine-edge = 1.22.2-r0
pkg:apk/alpine/go?arch=armhf&distro=alpine-3.20 = 1.22.2-r0
pkg:apk/alpine/go?arch=armhf&distro=alpine-3.19 = 1.21.9-r0
pkg:apk/alpine/go?arch=aarch64&distro=alpine-edge = 1.22.2-r0
pkg:apk/alpine/go?arch=aarch64&distro=alpine-3.20 = 1.22.2-r0
pkg:apk/alpine/go?arch=aarch64&distro=alpine-3.19 = 1.21.9-r0
pkg:apk/alpine/forgejo?arch=x86_64&distro=alpine-edge = 1.21.10.0-r0
pkg:apk/alpine/forgejo?arch=x86&distro=alpine-edge = 1.21.10.0-r0
pkg:apk/alpine/forgejo?arch=s390x&distro=alpine-edge = 1.21.10.0-r0
pkg:apk/alpine/forgejo?arch=riscv64&distro=alpine-edge = 1.21.10.0-r0
pkg:apk/alpine/forgejo?arch=ppc64le&distro=alpine-edge = 1.21.10.0-r0
pkg:apk/alpine/forgejo?arch=armv7&distro=alpine-edge = 1.21.10.0-r0
pkg:apk/alpine/forgejo?arch=armhf&distro=alpine-edge = 1.21.10.0-r0
pkg:apk/alpine/forgejo?arch=aarch64&distro=alpine-edge = 1.21.10.0-r0
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Fixed pkg:apk/alpine/rclone?arch=x86_64&distro=alpine-edge alpine rclone = 1.67.0-r0 alpine-edge x86_64
Fixed pkg:apk/alpine/rclone?arch=x86&distro=alpine-edge alpine rclone = 1.67.0-r0 alpine-edge x86
Fixed pkg:apk/alpine/rclone?arch=s390x&distro=alpine-edge alpine rclone = 1.67.0-r0 alpine-edge s390x
Fixed pkg:apk/alpine/rclone?arch=riscv64&distro=alpine-edge alpine rclone = 1.67.0-r0 alpine-edge riscv64
Fixed pkg:apk/alpine/rclone?arch=ppc64le&distro=alpine-edge alpine rclone = 1.67.0-r0 alpine-edge ppc64le
Fixed pkg:apk/alpine/rclone?arch=armv7&distro=alpine-edge alpine rclone = 1.67.0-r0 alpine-edge armv7
Fixed pkg:apk/alpine/rclone?arch=armhf&distro=alpine-edge alpine rclone = 1.67.0-r0 alpine-edge armhf
Fixed pkg:apk/alpine/rclone?arch=aarch64&distro=alpine-edge alpine rclone = 1.67.0-r0 alpine-edge aarch64
Fixed pkg:apk/alpine/go?arch=x86_64&distro=alpine-edge alpine go = 1.22.2-r0 alpine-edge x86_64
Fixed pkg:apk/alpine/go?arch=x86_64&distro=alpine-3.20 alpine go = 1.22.2-r0 alpine-3.20 x86_64
Fixed pkg:apk/alpine/go?arch=x86_64&distro=alpine-3.19 alpine go = 1.21.9-r0 alpine-3.19 x86_64
Fixed pkg:apk/alpine/go?arch=x86&distro=alpine-edge alpine go = 1.22.2-r0 alpine-edge x86
Fixed pkg:apk/alpine/go?arch=x86&distro=alpine-3.20 alpine go = 1.22.2-r0 alpine-3.20 x86
Fixed pkg:apk/alpine/go?arch=x86&distro=alpine-3.19 alpine go = 1.21.9-r0 alpine-3.19 x86
Fixed pkg:apk/alpine/go?arch=s390x&distro=alpine-edge alpine go = 1.22.2-r0 alpine-edge s390x
Fixed pkg:apk/alpine/go?arch=s390x&distro=alpine-3.20 alpine go = 1.22.2-r0 alpine-3.20 s390x
Fixed pkg:apk/alpine/go?arch=s390x&distro=alpine-3.19 alpine go = 1.21.9-r0 alpine-3.19 s390x
Fixed pkg:apk/alpine/go?arch=riscv64&distro=alpine-edge alpine go = 1.22.2-r0 alpine-edge riscv64
Fixed pkg:apk/alpine/go?arch=riscv64&distro=alpine-3.20 alpine go = 1.22.2-r0 alpine-3.20 riscv64
Fixed pkg:apk/alpine/go?arch=ppc64le&distro=alpine-edge alpine go = 1.22.2-r0 alpine-edge ppc64le
Fixed pkg:apk/alpine/go?arch=ppc64le&distro=alpine-3.20 alpine go = 1.22.2-r0 alpine-3.20 ppc64le
Fixed pkg:apk/alpine/go?arch=ppc64le&distro=alpine-3.19 alpine go = 1.21.9-r0 alpine-3.19 ppc64le
Fixed pkg:apk/alpine/go?arch=armv7&distro=alpine-edge alpine go = 1.22.2-r0 alpine-edge armv7
Fixed pkg:apk/alpine/go?arch=armv7&distro=alpine-3.20 alpine go = 1.22.2-r0 alpine-3.20 armv7
Fixed pkg:apk/alpine/go?arch=armv7&distro=alpine-3.19 alpine go = 1.21.9-r0 alpine-3.19 armv7
Fixed pkg:apk/alpine/go?arch=armhf&distro=alpine-edge alpine go = 1.22.2-r0 alpine-edge armhf
Fixed pkg:apk/alpine/go?arch=armhf&distro=alpine-3.20 alpine go = 1.22.2-r0 alpine-3.20 armhf
Fixed pkg:apk/alpine/go?arch=armhf&distro=alpine-3.19 alpine go = 1.21.9-r0 alpine-3.19 armhf
Fixed pkg:apk/alpine/go?arch=aarch64&distro=alpine-edge alpine go = 1.22.2-r0 alpine-edge aarch64
Fixed pkg:apk/alpine/go?arch=aarch64&distro=alpine-3.20 alpine go = 1.22.2-r0 alpine-3.20 aarch64
Fixed pkg:apk/alpine/go?arch=aarch64&distro=alpine-3.19 alpine go = 1.21.9-r0 alpine-3.19 aarch64
Fixed pkg:apk/alpine/forgejo?arch=x86_64&distro=alpine-edge alpine forgejo = 1.21.10.0-r0 alpine-edge x86_64
Fixed pkg:apk/alpine/forgejo?arch=x86&distro=alpine-edge alpine forgejo = 1.21.10.0-r0 alpine-edge x86
Fixed pkg:apk/alpine/forgejo?arch=s390x&distro=alpine-edge alpine forgejo = 1.21.10.0-r0 alpine-edge s390x
Fixed pkg:apk/alpine/forgejo?arch=riscv64&distro=alpine-edge alpine forgejo = 1.21.10.0-r0 alpine-edge riscv64
Fixed pkg:apk/alpine/forgejo?arch=ppc64le&distro=alpine-edge alpine forgejo = 1.21.10.0-r0 alpine-edge ppc64le
Fixed pkg:apk/alpine/forgejo?arch=armv7&distro=alpine-edge alpine forgejo = 1.21.10.0-r0 alpine-edge armv7
Fixed pkg:apk/alpine/forgejo?arch=armhf&distro=alpine-edge alpine forgejo = 1.21.10.0-r0 alpine-edge armhf
Fixed pkg:apk/alpine/forgejo?arch=aarch64&distro=alpine-edge alpine forgejo = 1.21.10.0-r0 alpine-edge aarch64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...