CVE-2019-16276

Description

Go before 1.12.10 and 1.13.x before 1.13.1 allow HTTP Request Smuggling.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
9.377

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2019-16276,CVE-2019-2989 are affected in IBM Spectrum Protect Server 8.1.9.300Windows
golang-1.11 security update(DSA-4534-1) golang-1.11_1.11.6-1+deb10u2_all.debLinux
(RHSA-2020:0329) go-toolset:rhel8 security update go-toolset-1.12.12-2.module+el8.1.0+5317+8a49ffbb.x86_64.rpmLinux
(RHSA-2020:0329) go-toolset:rhel8 security update golang-1.12.12-4.module+el8.1.0+5317+8a49ffbb.x86_64.rpmLinux
(RHSA-2020:0329) go-toolset:rhel8 security update golang-bin-1.12.12-4.module+el8.1.0+5317+8a49ffbb.x86_64.rpmLinux
(RHSA-2020:0329) go-toolset:rhel8 security update golang-docs-1.12.12-4.module+el8.1.0+5317+8a49ffbb.noarch.rpmLinux
(RHSA-2020:0329) go-toolset:rhel8 security update golang-misc-1.12.12-4.module+el8.1.0+5317+8a49ffbb.noarch.rpmLinux
(RHSA-2020:0329) go-toolset:rhel8 security update golang-race-1.12.12-4.module+el8.1.0+5317+8a49ffbb.x86_64.rpmLinux
(RHSA-2020:0329) go-toolset:rhel8 security update golang-src-1.12.12-4.module+el8.1.0+5317+8a49ffbb.noarch.rpmLinux
(RHSA-2020:0329) go-toolset:rhel8 security update golang-tests-1.12.12-4.module+el8.1.0+5317+8a49ffbb.noarch.rpmLinux
Kubeadm update (ELSA-2019-4816) kubeadm-1.12.10-1.0.10.el7.x86_64.rpmLinux
Kubeadm-ha-setup update (ELSA-2019-4816) kubeadm-ha-setup-0.0.2-1.0.68.el7.x86_64.rpmLinux
Kubeadm-upgrade update (ELSA-2019-4816) kubeadm-upgrade-0.0.1-1.0.27.el7.x86_64.rpmLinux
Kubectl update (ELSA-2019-4816) kubectl-1.12.10-1.0.10.el7.x86_64.rpmLinux
Kubelet update (ELSA-2019-4816) kubelet-1.12.10-1.0.10.el7.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234