CVE-2023-29406

Aliases:GO-2023-1878BIT-golang-2023-29406RHBA-2024:2274RHBA-2024:3053RHSA-2023:7202DEBIAN-CVE-2023-29406CGA-2659-pfmp-cxvgCGA-26pq-hpr7-6h9hCGA-29pp-hjg2-fq4mCGA-58v4-c3j5-vwxfCGA-5v3r-3mp4-g5cmCGA-68fg-c2hx-w9hmCGA-722w-xcp4-8wh9CGA-7c2q-cfqr-wm97CGA-88rj-v2fp-qp62CGA-8qfr-v85v-jw72CGA-99v8-66m5-cpmhCGA-9xwr-wqf5-499jCGA-h7rj-r6w5-v2cjCGA-hqpc-xmjr-6jxqCGA-hvgg-9qjq-5p25CGA-m9m8-qrwp-9qmrCGA-p98q-7qg6-pq36CGA-q9fx-xqv4-r9h6CGA-v45f-qx8v-g7j7CGA-vjj5-7fp9-vf43CGA-w2pq-69qh-3qhjCGA-x953-j7c9-fwp6CGA-xh27-9vx2-vcf3CGA-xjj5-p769-crr7CGA-946p-8jjx-w4r7CGA-g765-459q-7h69
Modified
Published: 11 Jul 2023, 19:23
Last modified:13 Feb 2025, 16:49

Vulnerability Summary

Overall Risk (default)
medium
26/100
CVSS Score
6.5 MEDIUM
v3.1 (nvd)
EPSS Score
1.45% LOW
1% probability +1.19%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

11 Jul 2023, 19:23
Published
Vulnerability first disclosed
13 Feb 2025, 16:49
Last Modified
Vulnerability information updated

Description

The HTTP/1 client does not fully validate the contents of the Host header. A maliciously crafted Host header can inject additional headers or entire requests. With fix, the HTTP/1 client now refuses to send requests containing an invalid Request.Host or Request.URL.Host value.

CVSS Metrics

  • v3.1MEDIUMScore: 6.5CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

EPSS Trends

Current EPSS score: 1.45% Percentile: 72%

Techniques & Countermeasures

  • CWE-436Interpretation Conflict

    Product A handles inputs or steps differently than Product B, which causes A to perform incorrect actions based on its perception of B's state.

Affected Systems

  • chainguardgo-1.20

    < 1.20.6-r0

  • chainguardgo-1.21

    all

  • chainguardkatib-earlystopping

    < 0.19.0-r31

  • chainguardkatib-suggestion-goptuna-compat

    all

  • chainguardkatib-suggestion-hyperband

    < 0.19.0-r31

  • chainguardkatib-suggestion-hyperopt

    < 0.19.0-r31 | < 0.19.0-r40

  • chainguardkatib-suggestion-nas-darts

    < 0.19.0-r31

  • chainguardkatib-suggestion-nas-enas

    < 0.19.0-r31

  • chainguardkatib-suggestion-optuna-enas

    < 0.19.0-r31

  • chainguardkatib-suggestion-pbt-enas

    < 0.19.0-r31

  • chainguardkatib-suggestion-skopt-enas

    < 0.19.0-r31

  • chainguardkatib-tfevent-metricscollector

    < 0.19.0-r31

  • chainguardkind

    < 0.21.0-r0

  • wolfigo-1.20

    < 1.20.6-r0

  • wolfigo-1.21

    all

  • wolfikatib-earlystopping

    < 0.19.0-r31

  • wolfikatib-suggestion-goptuna-compat

    all

  • wolfikatib-suggestion-hyperband

    < 0.19.0-r31

  • wolfikatib-suggestion-hyperopt

    < 0.19.0-r31 | < 0.19.0-r40

  • wolfikatib-suggestion-nas-darts

    < 0.19.0-r31

  • wolfikatib-suggestion-nas-enas

    < 0.19.0-r31

  • wolfikatib-suggestion-optuna-enas

    < 0.19.0-r31

  • wolfikatib-suggestion-pbt-enas

    < 0.19.0-r31

  • wolfikatib-suggestion-skopt-enas

    < 0.19.0-r31

  • wolfikatib-tfevent-metricscollector

    < 0.19.0-r31

  • wolfikind

    < 0.21.0-r0

  • debiangolang-1.15

    all

  • debiangolang-1.19

    all

  • go standard librarynet/http

    < 1.19.11 | ≥ 1.20.0-0, < 1.20.6

  • golanggo

    < 1.19.11 | ≥ 1.20.0, < 1.20.6

  • Gostdlib

    ≥ 1.20.0-0, < 1.20.6

  • redhataardvark-dns

    < 2:1.0.1-38.module+el8.9.0+20325+b2853e6e

  • redhatbuildah

    < 1:1.24.6-7.module+el8.9.0+20325+b2853e6e

  • redhatbuildah-debuginfo

    < 1:1.24.6-7.module+el8.9.0+20325+b2853e6e

  • redhatbuildah-debugsource

    < 1:1.24.6-7.module+el8.9.0+20325+b2853e6e

  • redhatbuildah-tests

    < 1:1.24.6-7.module+el8.9.0+20325+b2853e6e

  • redhatbuildah-tests-debuginfo

    < 1:1.24.6-7.module+el8.9.0+20325+b2853e6e

  • redhatcockpit-podman

    < 0:46-1.module+el8.9.0+20325+b2853e6e

  • redhatconmon

    < 2:2.1.4-2.module+el8.9.0+20325+b2853e6e

  • redhatconmon-debuginfo

    < 2:2.1.4-2.module+el8.9.0+20325+b2853e6e

  • redhatconmon-debugsource

    < 2:2.1.4-2.module+el8.9.0+20325+b2853e6e

  • redhatcontainer-selinux

    < 2:2.205.0-3.module+el8.9.0+20325+b2853e6e

  • redhatcontainernetworking-plugins

    < 1:1.1.1-5.module+el8.9.0+20325+b2853e6e

  • redhatcontainernetworking-plugins-debuginfo

    < 1:1.1.1-5.module+el8.9.0+20325+b2853e6e

  • redhatcontainernetworking-plugins-debugsource

    < 1:1.1.1-5.module+el8.9.0+20325+b2853e6e

  • redhatcontainers-common

    < 2:1-38.module+el8.9.0+20325+b2853e6e

  • redhatcrit

    < 0:3.15-3.module+el8.9.0+20325+b2853e6e

  • redhatcriu

    < 0:3.15-3.module+el8.9.0+20325+b2853e6e

  • redhatcriu-debuginfo

    < 0:3.15-3.module+el8.9.0+20325+b2853e6e

  • redhatcriu-debugsource

    < 0:3.15-3.module+el8.9.0+20325+b2853e6e

Showing first 50 affected entries in server-rendered view.

References (22)