Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-29406
HistoryJul 11, 2023 - 12:00 a.m.

CVE-2023-29406

2023-07-1100:00:00
ubuntu.com
ubuntu.com
19
cve-2023-29406
host header validation
malicious injection
http/1 client
golang package
rebuild

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

0.001 Low

EPSS

Percentile

39.1%

The HTTP/1 client does not fully validate the contents of the Host header.
A maliciously crafted Host header can inject additional headers or entire
requests. With fix, the HTTP/1 client now refuses to send requests
containing an invalid Request.Host or Request.URL.Host value.

Notes

Author Note
mdeslaur Packages built using golang need to be rebuilt once the vulnerability has been fixed. This CVE entry does not list packages that need rebuilding outside of the main repository or the Ubuntu variants with PPA overlays.

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

0.001 Low

EPSS

Percentile

39.1%