Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:36442
HistoryJul 22, 2022 - 5:05 p.m.

Information Disclosure

2022-07-2217:05:45
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14
go
vulnerability
reverseproxy
information disclosure
security mechanism

EPSS

0.002

Percentile

52.0%

go is vulnerable to information disclosure. The vulnerability exists in httputil.ReverseProxy.ServeHTTP with a Request.Header map containing nil value for the X-Forwarded-For header which allows to remote attacker to bypass security mechanism and access the sensitive information