Upstream information
Description
net/url in Go before 1.11.13 and 1.12.x before 1.12.8 mishandles malformed hosts in URLs, leading to an authorization bypass in some applications. This is related to a Host field with a suffix appearing in neither Hostname() nor Port(), and is related to a non-numeric port number. For example, an attacker can compose a crafted javascript:// URL that results in a hostname of google.com.SUSE information
Overall state of this security issue: Resolved
This issue is currently rated as having critical severity.
National Vulnerability Database | |
---|---|
Base Score | 7.5 |
Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Access Vector | Network |
Access Complexity | Low |
Authentication | None |
Confidentiality Impact | Partial |
Integrity Impact | Partial |
Availability Impact | Partial |
National Vulnerability Database | |
---|---|
Base Score | 9.8 |
Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Attack Vector | Network |
Attack Complexity | Low |
Privileges Required | None |
User Interaction | None |
Scope | Unchanged |
Confidentiality Impact | High |
Integrity Impact | High |
Availability Impact | High |
CVSSv3 Version | 3 |
SUSE Security Advisories:
- SUSE-SU-2019:2213-1, published Fri Aug 23 13:11:27 MDT 2019
- SUSE-SU-2019:2214-1, published Fri Aug 23 13:12:28 MDT 2019
- openSUSE-SU-2019:2000-1, published Sat, 24 Aug 2019 18:12:22 +0200 (CEST)
- openSUSE-SU-2019:2056-1, published Mon, 2 Sep 2019 18:14:05 +0200 (CEST)
- openSUSE-SU-2019:2072-1, published Thu, 5 Sep 2019 15:11:31 +0200 (CEST)
- openSUSE-SU-2019:2085-1, published Sat, 7 Sep 2019 21:11:24 +0200 (CEST)
- openSUSE-SU-2019:2130-1, published Sat, 14 Sep 2019 18:10:28 +0200 (CEST)
List of released packages
Product(s) | Fixed package version(s) | References |
---|---|---|
openSUSE Leap 15.0 |
| Patchnames: openSUSE-2019-2056 openSUSE-2019-2072 |
openSUSE Leap 15.1 |
| Patchnames: openSUSE-2019-2000 openSUSE-2019-2056 openSUSE-2019-2072 openSUSE-2019-2085 openSUSE-2019-2130 |
openSUSE Tumbleweed |
| Patchnames: openSUSE Tumbleweed GA go1.11-1.11.13-10.5 openSUSE Tumbleweed GA go1.12-1.12.17-4.8 |
SUSE Timeline for this CVE
CVE page created: Wed Aug 14 05:20:35 2019CVE page last modified: Tue Feb 7 21:57:54 2023