HIGH 7.5 Go
github.com/pires/go-proxyproto vulnerable to DoS via Connection descriptor exhaustion
GHSA-xcf7-q56x-78gh · CVE-2021-23409 · GO-2022-0233
Published · Modified
Description
The package github.com/pires/go-proxyproto before 0.6.1 is vulnerable to Denial of Service (DoS) via creating connections without the proxy protocol header. While this issue was patched in 0.6.0, the fix introduced additional issues which were subsequently patched in 0.6.1.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2021-23409
- WEB https://github.com/pires/go-proxyproto/issues/65
- WEB https://github.com/pires/go-proxyproto/issues/75
- WEB https://github.com/pires/go-proxyproto/pull/74
- WEB https://github.com/pires/go-proxyproto/pull/74/commits/cdc63867da24fc609b727231f682670d0d1cd346
- WEB https://github.com/pires/go-proxyproto/pull/76
- WEB https://github.com/pires/go-proxyproto/commit/2e44d7a76a851d66890ab341403253afae5caac2
- PACKAGE https://github.com/pires/go-proxyproto
- WEB https://github.com/pires/go-proxyproto/releases/tag/v0.6.0
- WEB https://github.com/pires/go-proxyproto/releases/tag/v0.6.1
- WEB https://pkg.go.dev/vuln/GO-2022-0233
- WEB https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMPIRESGOPROXYPROTO-1316439
Ready to move
Start Securing
Free, no credit card | First findings in minutes