[GO-2024-2600] Incorrect forwarding of sensitive headers and cookies on HTTP redirect in net/http
Affected Packages
4
Fixed Packages
4
CVEs
1
When following an HTTP redirect to a domain which is not a subdomain match or
exact match of the initial domain, an http.Client does not forward sensitive
headers such as "Authorization" or "Cookie". For example, a redirect from
foo.com to www.foo.com will forward the Authorization header, but a redirect to
bar.com will not.
A maliciously crafted HTTP redirect could cause sensitive headers to be
unexpectedly forwarded.
Package | Affected Version |
---|---|
pkg:golang/net/http/cookiejar | >= 1.22.0, < 1.21.8 |
pkg:golang/net/http/cookiejar | >= 1.22.0, < 1.22.1 |
pkg:golang/net/http | >= 1.22.0, < 1.21.8 |
pkg:golang/net/http | >= 1.22.0, < 1.22.1 |
Package | Fixed Version |
---|---|
pkg:golang/net/http/cookiejar | = 1.21.8 |
pkg:golang/net/http/cookiejar | = 1.22.1 |
pkg:golang/net/http | = 1.21.8 |
pkg:golang/net/http | = 1.22.1 |
- ID
- GO-2024-2600
- URL
- https://pkg.go.dev/vuln/GO-2024-2600
- Published
-
2024-03-05T21:34:02
(6 months ago) - Modified
-
2024-07-17T19:54:18
(2 months ago) - Other Advisories
-
- ALAS2-2024-2554
- ALPINE:CVE-2023-45289
- ALSA-2024:2562
- ALSA-2024:2724
- ALSA-2024:3259
- ALSA-2024:3346
- ELSA-2024-2562
- ELSA-2024-2724
- ELSA-2024-3259
- ELSA-2024-3346
- FREEBSD:B1B039EC-DBFC-11EE-9165-901B0E9408DC
- GLSA-202408-07
- RHSA-2024:2562
- RHSA-2024:2724
- RHSA-2024:3259
- RHSA-2024:3346
- RLSA-2024:2562
- RLSA-2024:2724
- RLSA-2024:3346
- SUSE-SU-2024:0800-1
- SUSE-SU-2024:0811-1
- SUSE-SU-2024:0812-1
- SUSE-SU-2024:0936-1
- SUSE-SU-2024:3089-1
- USN-6886-1
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Fixed | pkg:golang/net/http/cookiejar | net/http | cookiejar | = 1.21.8 | |||
Affected | pkg:golang/net/http/cookiejar | net/http | cookiejar | >= 1.22.0 < 1.21.8 | |||
Fixed | pkg:golang/net/http/cookiejar | net/http | cookiejar | = 1.22.1 | |||
Affected | pkg:golang/net/http/cookiejar | net/http | cookiejar | >= 1.22.0 < 1.22.1 | |||
Fixed | pkg:golang/net/http | net | http | = 1.21.8 | |||
Affected | pkg:golang/net/http | net | http | >= 1.22.0 < 1.21.8 | |||
Fixed | pkg:golang/net/http | net | http | = 1.22.1 | |||
Affected | pkg:golang/net/http | net | http | >= 1.22.0 < 1.22.1 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |