CVE-2019-16276
Description
Go before 1.12.10 and 1.13.x before 1.13.1 allow HTTP Request Smuggling.
Risk Information
Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
9.377
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Vulnerabilities CVE-2019-16276,CVE-2019-2989 are affected in IBM Spectrum Protect Server 8.1.9.300 | Windows |
| golang-1.11 security update(DSA-4534-1) golang-1.11_1.11.6-1+deb10u2_all.deb | Linux |
| (RHSA-2020:0329) go-toolset:rhel8 security update go-toolset-1.12.12-2.module+el8.1.0+5317+8a49ffbb.x86_64.rpm | Linux |
| (RHSA-2020:0329) go-toolset:rhel8 security update golang-1.12.12-4.module+el8.1.0+5317+8a49ffbb.x86_64.rpm | Linux |
| (RHSA-2020:0329) go-toolset:rhel8 security update golang-bin-1.12.12-4.module+el8.1.0+5317+8a49ffbb.x86_64.rpm | Linux |
| (RHSA-2020:0329) go-toolset:rhel8 security update golang-docs-1.12.12-4.module+el8.1.0+5317+8a49ffbb.noarch.rpm | Linux |
| (RHSA-2020:0329) go-toolset:rhel8 security update golang-misc-1.12.12-4.module+el8.1.0+5317+8a49ffbb.noarch.rpm | Linux |
| (RHSA-2020:0329) go-toolset:rhel8 security update golang-race-1.12.12-4.module+el8.1.0+5317+8a49ffbb.x86_64.rpm | Linux |
| (RHSA-2020:0329) go-toolset:rhel8 security update golang-src-1.12.12-4.module+el8.1.0+5317+8a49ffbb.noarch.rpm | Linux |
| (RHSA-2020:0329) go-toolset:rhel8 security update golang-tests-1.12.12-4.module+el8.1.0+5317+8a49ffbb.noarch.rpm | Linux |
| Kubeadm update (ELSA-2019-4816) kubeadm-1.12.10-1.0.10.el7.x86_64.rpm | Linux |
| Kubeadm-ha-setup update (ELSA-2019-4816) kubeadm-ha-setup-0.0.2-1.0.68.el7.x86_64.rpm | Linux |
| Kubeadm-upgrade update (ELSA-2019-4816) kubeadm-upgrade-0.0.1-1.0.27.el7.x86_64.rpm | Linux |
| Kubectl update (ELSA-2019-4816) kubectl-1.12.10-1.0.10.el7.x86_64.rpm | Linux |
| Kubelet update (ELSA-2019-4816) kubelet-1.12.10-1.0.10.el7.x86_64.rpm | Linux |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234