CVE-2021-29923
Description
Go before 1.17 does not properly consider extraneous zero characters at the beginning of an IP address octet, which (in some situations) allows attackers to bypass access control that is based on IP addresses, because of unexpected octal interpretation. This affects net.ParseIP and net.ParseCIDR.
Risk Information
Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
0.115
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| (RHSA-2021:3585) go-toolset:rhel8 security update go-toolset-1.15.14-2.module+el8.4.0+12542+e3fec473.x86_64.rpm | Linux |
| (RHSA-2021:3585) go-toolset:rhel8 security update golang-1.15.14-2.module+el8.4.0+12542+e3fec473.x86_64.rpm | Linux |
| (RHSA-2021:3585) go-toolset:rhel8 security update golang-bin-1.15.14-2.module+el8.4.0+12542+e3fec473.x86_64.rpm | Linux |
| (RHSA-2021:3585) go-toolset:rhel8 security update golang-docs-1.15.14-2.module+el8.4.0+12542+e3fec473.noarch.rpm | Linux |
| (RHSA-2021:3585) go-toolset:rhel8 security update golang-misc-1.15.14-2.module+el8.4.0+12542+e3fec473.noarch.rpm | Linux |
| (RHSA-2021:3585) go-toolset:rhel8 security update golang-race-1.15.14-2.module+el8.4.0+12542+e3fec473.x86_64.rpm | Linux |
| (RHSA-2021:3585) go-toolset:rhel8 security update golang-src-1.15.14-2.module+el8.4.0+12542+e3fec473.noarch.rpm | Linux |
| (RHSA-2021:3585) go-toolset:rhel8 security update golang-tests-1.15.14-2.module+el8.4.0+12542+e3fec473.noarch.rpm | Linux |
| Delve update (ELSA-2021-3585) delve-1.5.0-2.0.1.module+el8.4.0+20021+8a86d991.x86_64.rpm | Linux |
| Go-toolset update (ELSA-2021-3585) go-toolset-1.15.14-2.module+el8.4.0+20307+d24cc4c6.x86_64.rpm | Linux |
| Golang update (ELSA-2021-3585) golang-1.15.14-1.module+el8.4.0+20307+d24cc4c6.x86_64.rpm | Linux |
| Golang-bin update (ELSA-2021-3585) golang-bin-1.15.14-1.module+el8.4.0+20307+d24cc4c6.x86_64.rpm | Linux |
| Golang-docs update (ELSA-2021-3585) golang-docs-1.15.14-1.module+el8.4.0+20307+d24cc4c6.noarch.rpm | Linux |
| Golang-misc update (ELSA-2021-3585) golang-misc-1.15.14-1.module+el8.4.0+20307+d24cc4c6.noarch.rpm | Linux |
| Golang-race update (ELSA-2021-3585) golang-race-1.15.14-1.module+el8.4.0+20307+d24cc4c6.x86_64.rpm | Linux |
| Golang-src update (ELSA-2021-3585) golang-src-1.15.14-1.module+el8.4.0+20307+d24cc4c6.noarch.rpm | Linux |
| Golang-tests update (ELSA-2021-3585) golang-tests-1.15.14-1.module+el8.4.0+20307+d24cc4c6.noarch.rpm | Linux |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234