2020-08-19
ALT-BU-2020-3983-1
Branch sisyphus update bulletin.
Closed vulnerabilities
Published: 2020-09-02
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2020-24553
Go before 1.14.8 and 1.15.x before 1.15.1 allows XSS because text/html is the default for CGI/FCGI handlers that lack a Content-Type header.
Severity: MEDIUM (6.1)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
References:
- openSUSE-SU-2020:1584
- openSUSE-SU-2020:1584
- openSUSE-SU-2020:1587
- openSUSE-SU-2020:1587
- http://packetstormsecurity.com/files/159049/Go-CGI-FastCGI-Transport-Cross-Site-Scripting.html
- http://packetstormsecurity.com/files/159049/Go-CGI-FastCGI-Transport-Cross-Site-Scripting.html
- http://seclists.org/fulldisclosure/2020/Sep/5
- http://seclists.org/fulldisclosure/2020/Sep/5
- 20200902 [RT-SA-2020-004] Inconsistent Behavior of Go's CGI and FastCGI Transport May Lead to Cross-Site Scripting
- 20200902 [RT-SA-2020-004] Inconsistent Behavior of Go's CGI and FastCGI Transport May Lead to Cross-Site Scripting
- https://groups.google.com/forum/#%21topic/golang-announce/8wqlSbkLdPs
- https://groups.google.com/forum/#%21topic/golang-announce/8wqlSbkLdPs
- FEDORA-2020-741cfa13d0
- FEDORA-2020-741cfa13d0
- https://security.netapp.com/advisory/ntap-20200924-0003/
- https://security.netapp.com/advisory/ntap-20200924-0003/
- https://www.oracle.com//security-alerts/cpujul2021.html
- https://www.oracle.com//security-alerts/cpujul2021.html
- https://www.oracle.com/security-alerts/cpuApr2021.html
- https://www.oracle.com/security-alerts/cpuApr2021.html
- https://www.redteam-pentesting.de/advisories/rt-sa-2020-004
- https://www.redteam-pentesting.de/advisories/rt-sa-2020-004