GO-2022-0520
Dashboard / Vulnerabilities / GO-2022-0520
GO-2022-0520
Summary: Exposure of client IP addresses in net/http
Details: Client IP adresses may be unintentionally exposed via X-Forwarded-For headers. When httputil.ReverseProxy.ServeHTTP is called with a Request.Header map containing a nil value for the X-Forwarded-For header, ReverseProxy sets the client IP as the value of the X-Forwarded-For header, contrary to its documentation. In the more usual case where a Director function sets the X-Forwarded-For header value to nil, ReverseProxy leaves the header unmodified as expected.
References: https://go.dev/cl/412857, https://go.googlesource.com/go/+/b2cc0fecc2ccd80e6d5d16542cc684f97b3a9c8a, https://go.dev/issue/53423, https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE
Affected packages
Package
Name: stdlib
Purl: pkg:golang/stdlib
Affected ranges
Type: SEMVER
Events:
