CVE-2021-33197 log
Source |
|
Severity | Medium |
Remote | Yes |
Type | Url request injection |
Description | A security issue has been found in Go before version 1.16.5. ReverseProxy in net/http/httputil could be made to forward certain hop-by-hop headers, including Connection. In case the target of the ReverseProxy was itself a reverse proxy, this would let an attacker drop arbitrary headers, including those set by the ReverseProxy.Director. |
Group | Package | Affected | Fixed | Severity | Status | Ticket |
---|---|---|---|---|---|---|
AVG-2006 | go | 2:1.16.4-1 | 2:1.16.5-1 | Medium | Fixed |
Date | Advisory | Group | Package | Severity | Type |
---|---|---|---|---|---|
15 Jun 2021 | ASA-202106-42 | AVG-2006 | go | Medium | multiple issues |