UBUNTU-CVE-2023-45289
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-45289
UBUNTU-CVE-2023-45289
Summary:
Details: When following an HTTP redirect to a domain which is not a subdomain match or exact match of the initial domain, an http.Client does not forward sensitive headers such as "Authorization" or "Cookie". For example, a redirect from foo.com to www.foo.com will forward the Authorization header, but a redirect to bar.com will not. A maliciously crafted HTTP redirect could cause sensitive headers to be unexpectedly forwarded.
References: https://ubuntu.com/security/CVE-2023-45289, https://github.com/golang/go/issues/65065, https://github.com/golang/go/commit/3a855208e3efed2e9d7c20ad023f1fa78afcc0be, https://github.com/golang/go/commit/20586c0dbe03d144f914155f879fa5ee287591a1, https://go.dev/issue/65065, https://go.dev/cl/569340, https://groups.google.com/g/golang-announce/c/5pwGVUPoMbg, https://pkg.go.dev/vuln/GO-2024-2600, https://www.cve.org/CVERecord?id=CVE-2023-45289, https://ubuntu.com/security/notices/USN-6886-1
Affected packages
Package
Name: golang-1.10
Purl: pkg:deb/ubuntu/golang-1.10?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
