CVE Feed

    Dashboard / CVE / CVE-2023-29401

    CVE-2023-29401

    The filename parameter of the Context.FileAttachment function is not properly sanitized. A maliciously crafted filename can cause the Content-Disposition header to be sent with an unexpected filename value or otherwise modify the Content-Disposition header. For example, a filename of "setup.bat";x=.txt" will be sent as a file named "setup.bat". If the FileAttachment function is called with names provided by an untrusted source, this may permit an attacker to cause a file to be served with a name different than provided. Maliciously crafted attachment file name can modify the Content-Disposition header.

    Published:Jun 8, 2023
    Last Modified:Jan 6, 2025
    EPS:Jun 8, 2023
    EPSS Score:0.00374
    CVSS Score:4.3

    Affected Products

    Vendor
    Gin-gonic
    Product
    Gin
    Vendor
    Redhat
    Product
    Migration Toolkit Virtualization
    Vendor
    Redhat
    Product
    Openshift
    Vendor
    Redhat
    Product
    Rhmt

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High