Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-29406
HistoryJul 11, 2023 - 8:15 p.m.

Design/Logic Flaw

2023-07-1120:15:00
PRIOn knowledge base
www.prio-n.com
12
http
client
logic flaw
validation
host header
nvd

6.8 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

39.1%

The HTTP/1 client does not fully validate the contents of the Host header. A maliciously crafted Host header can inject additional headers or entire requests. With fix, the HTTP/1 client now refuses to send requests containing an invalid Request.Host or Request.URL.Host value.

CPENameOperatorVersion
goge1.20.0
golt1.20.6
golt1.19.11