Improper Neutralization of HTTP Headers for Scripting Syntax in Go programming language - CVE-2023-29406

 

Improper Neutralization of HTTP Headers for Scripting Syntax in Go programming language - CVE-2023-29406

Published: July 17, 2023


Vulnerability identifier: #VU78327
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-29406
CWE-ID: CWE-644
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to improper input validation in HTTP/1 client when handling HTTP Host header. A remote non-authenticated attacker can send a specially crafted HTTP request with a maliciously crafted Host header and inject additional headers or entire requests.

Successful exploitation of the vulnerability may allow an attacker to perform cross-site scripting, cache poisoning or session hijacking attacks.


Affected software

Go programming language
Amazon Linux AMI
Gentoo Linux
Oracle Linux
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
Fedora
Anolis OS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Development Tools Module
openSUSE Leap
Ubuntu
openEuler
Red Hat OpenShift Serverless
OpenShift Data Foundation (formerly OpenShift Container Storage)
Run Once Duration Override Operator for Red Hat OpenShift
Service Telemetry Framework
Consul Enterprise
Cryostat
IBM Spectrum Copy Data Management
Red Hat OpenShift distributed tracing (RHOSDT)
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Red Hat Advanced Cluster Security for Kubernetes
OpenShift Logging
Red Hat OpenStack
Operations Dashboard
Automation Assets in IBM Cloud Pak for Integration (CP4I)
IBM Cloud Transformation Advisor
IBM Cloud Pak for Data Scheduling
IBM Watson Discovery for IBM Cloud Pak for Data
App Connect Enterprise Certified Container
Red Hat Migration Toolkit for Applications
Red Hat Satellite
Azure Stack
IBM Cloud Pak for Business Automation
IBM Observability with Instana
OpenShift API for Data Protection (OADP)
Secondary Scheduler Operator for Red Hat OpenShift (OSSO)
Network Observability plugin for the Openshift Console
Migration Toolkit for Containers
OpenShift Serverless Client
IBM Cloud Pak for Multicloud Management
Red Hat OpenShift Container Platform
IBM Business Automation Manager Open Editions
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
ObjectScale
Cloud Pak for Network Automation
IBM Cloud Pak for Watson AIOps
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
Storage Protect Server
IBM Sterling Order Management
Storage Protect Plus Container Agent
Storage Protect Plus Server
Robotic Process Automation for Cloud Pak
Splunk Enterprise
golang-1.18-src (Ubuntu package)
golang-1.18-go (Ubuntu package)
golang-1.18 (Ubuntu package)
toolbox-tests
toolbox
toolbox (Red Hat package)
udica
amazon-ecr-credential-helper
nerdctl
runc
cni-plugins
slirp4netns
oci-seccomp-bpf-hook
containernetworking-plugins (Red Hat package)
containernetworking-plugins
python-octavia-tests-tempest (Red Hat package)
containerd
skopeo-debuginfo
containers-common
skopeo
skopeo-debugsource
aardvark-dns
netavark
crun
openshift-serverless-clients (Red Hat package)
fuse-overlayfs
skopeo (Red Hat package)
skopeo-tests
golang
golang-devel
golang-help
golang-1.17-go (Ubuntu package)
golang-1.17 (Ubuntu package)
golang-1.17-src (Ubuntu package)
go1.19-race
go1.19-doc
go1.19
go1.19-openssl-doc
go1.19-openssl
go1.19-openssl-race
go1.20-openssl-race
go1.20-openssl-doc
go1.20-openssl
go1.20-openssl-debuginfo
go1.20
go1.20-doc
go1.20-race
go1.20-debuginfo
golang-bin
golang-shared
golang-docs
golang-misc
golang-src
golang-tests
dev-lang/go
cri-o (Red Hat package)
buildah
buildah-tests
buildah (Red Hat package)
ecs-init
conmon
container-selinux
container-selinux (Red Hat package)
amazon-ssm-agent
etcd (Red Hat package)
etcd
etcdctl
criu-libs
criu-devel
criu
crit
python3-criu
libslirp
libslirp-devel
python3-podman
podman (Red Hat package)
podman-docker
podman
podman-catatonit
podman-tests
podman-gvproxy
podman-plugins
podman-remote
openshift-clients (Red Hat package)
openshift (Red Hat package)
kernel (Red Hat package)
kernel-rt (Red Hat package)
ovn23.09 (Red Hat package)
docker
cockpit-podman
IBM Cloud Pak System
Dell EMC VxRail Appliance
Operational Decision Manager
Event Streams

How to mitigate CVE-2023-29406

Install updates from vendor's website.

Go programming language - addressed in versions 1.19.11, 1.20.6
Red Hat OpenShift Serverless - update to 1.30.2
Run Once Duration Override Operator for Red Hat OpenShift - update to 1.0.1
Secondary Scheduler Operator for Red Hat OpenShift (OSSO) - update to 1.1.3
Service Telemetry Framework - update to 1.5.2
Migration Toolkit for Containers - update to 1.7.14
Consul Enterprise - addressed in versions 1.14.9, 1.15.5, 1.16.1
OpenShift Serverless Client - update to 1.30.2
IBM Spectrum Copy Data Management - update to 2.2.21.0
IBM Cloud Pak for Multicloud Management - update to 2.3.8
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.0
Red Hat Advanced Cluster Security for Kubernetes - update to 4.4.0
Red Hat OpenShift Container Platform - addressed in versions 4.12.45, 4.13.22, 4.13.24, 4.14.2, 4.14.4
OpenShift Logging - addressed in versions 5.6.12, 5.7.7
IBM Business Automation Manager Open Editions - update to 9.0.1
Splunk Enterprise - addressed in versions 9.0.8, 9.1.3
Red Hat OpenStack - update to 16.2.5
Operations Dashboard - update to 2022.2.1-14-lts
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - addressed in versions 2022.2.1-12, 2023.2.1-2
Automation Assets in IBM Cloud Pak for Integration (CP4I) - update to 2022.2.1-11
golang-1.18-src (Ubuntu package) - addressed in versions Ubuntu Pro, 1.18.1-1ubuntu1.2, 1.18.1-1ubuntu1~20.04.3
golang-1.18-go (Ubuntu package) - addressed in versions Ubuntu Pro, 1.18.1-1ubuntu1.2, 1.18.1-1ubuntu1~20.04.3
golang-1.18 (Ubuntu package) - addressed in versions Ubuntu Pro, 1.18.1-1ubuntu1.2, 1.18.1-1ubuntu1~20.04.3
toolbox-tests - update to 0.0.99.4-5.0.1
toolbox - update to 0.0.99.4-5.0.1
toolbox (Red Hat package) - update to 0.0.99.4-6.el9_3
udica - update to 0.2.6-20
amazon-ecr-credential-helper - update to 0.7.1-2
nerdctl - update to 1.1.0-1
runc - update to 1.1.7-1
runc - update to 1.1.12-1.0.1
cni-plugins - update to 1.2.0-1
slirp4netns - update to 1.2.1-1
oci-seccomp-bpf-hook - update to 1.2.9-1
containernetworking-plugins (Red Hat package) - update to 1.3.0-4.el9
containernetworking-plugins - update to 1.3.0-8.0.1
ObjectScale - update to 1.4.0
python-octavia-tests-tempest (Red Hat package) - update to 1.4.1-2.20230111145026.f7718ef.el8ost
containerd - addressed in versions 1.4.13-5, 1.7.2-1
skopeo-debuginfo - addressed in versions 1.5.2-6, 1.5.2-7, 1.8.0-5
containers-common - addressed in versions 1.5.2-6, 1.5.2-7
skopeo - addressed in versions 1.5.2-6, 1.5.2-7, 1.8.0-5
skopeo-debugsource - addressed in versions 1.5.2-6, 1.5.2-7, 1.8.0-5
aardvark-dns - update to 1.7.0-2.0.1
netavark - update to 1.7.0-2.0.1
crun - update to 1.8.7-1
openshift-serverless-clients (Red Hat package) - update to 1.9.2-4.el8
fuse-overlayfs - update to 1.12-1.0.1
skopeo (Red Hat package) - update to 1.13.3-1.el9
skopeo - update to 1.13.3-3.0.1
skopeo-tests - update to 1.13.3-3.0.1
golang - addressed in versions 1.15.7-31, 1.17.3-20
golang-devel - addressed in versions 1.15.7-31, 1.17.3-20
golang-help - addressed in versions 1.15.7-31, 1.17.3-20
golang-1.17-go (Ubuntu package) - update to 1.17.13-3ubuntu1.2
golang-1.17 (Ubuntu package) - update to 1.17.13-3ubuntu1.2
golang-1.17-src (Ubuntu package) - update to 1.17.13-3ubuntu1.2
go1.19-race - update to 1.19.11-150000.1.37.1
go1.19-doc - update to 1.19.11-150000.1.37.1
go1.19 - update to 1.19.11-150000.1.37.1
golang - update to 1.19.13-1.el7
go1.19-openssl-doc - update to 1.19.13.1-150000.1.8.1
go1.19-openssl - update to 1.19.13.1-150000.1.8.1
go1.19-openssl-race - update to 1.19.13.1-150000.1.8.1
golang - addressed in versions 1.20.6-1, 1.20.8-1.47
go1.20-openssl-race - update to 1.20.6.1-150000.1.8.1
go1.20-openssl-doc - update to 1.20.6.1-150000.1.8.1
go1.20-openssl - update to 1.20.6.1-150000.1.8.1
go1.20-openssl-debuginfo - update to 1.20.6.1-150000.1.8.1
go1.20 - update to 1.20.6-150000.1.17.1
go1.20-doc - update to 1.20.6-150000.1.17.1
go1.20-race - update to 1.20.6-150000.1.17.1
go1.20-debuginfo - update to 1.20.6-150000.1.17.1
golang - update to 1.20.9-1
golang-bin - update to 1.20.9-1
golang-shared - update to 1.20.9-1
golang-docs - update to 1.20.9-1
golang-misc - update to 1.20.9-1
golang-src - update to 1.20.9-1
golang-tests - update to 1.20.9-1
dev-lang/go - update to 1.20.10
cri-o (Red Hat package) - addressed in versions 1.27.1-13.1.rhaos4.14.git956c5f7.el8, 1.27.1-13.1.rhaos4.14.git956c5f7.el9, 1.27.3-2.rhaos4.14.git03502b6.el8, 1.27.3-2.rhaos4.14.git03502b6.el9
buildah - update to 1.31.3-1
buildah-tests - update to 1.31.3-1
buildah (Red Hat package) - update to 1.31.3-1.el9
containers-common - update to 1-71.0.1
ecs-init - update to 1.75.0-1
conmon - update to 2.1.8-1
IBM Cloud Pak System - update to 2.3.3.6 iFix 1
Cloud Pak for Network Automation - update to 2.7
container-selinux - update to 2.221.0-1
container-selinux (Red Hat package) - addressed in versions 2.223.0-1.rhaos4.14.el8, 2.223.0-2.rhaos4.14.el9
amazon-ssm-agent - update to 3.2.1630.0-1
etcd (Red Hat package) - update to 3.3.23-15.el8ost
etcd - update to 3.4.14-11
etcd - update to 3.5.12-150000.7.6.1
etcdctl - update to 3.5.12-150000.7.6.1
IBM Cloud Transformation Advisor - update to 3.7.0
criu-libs - update to 3.18-5
criu-devel - update to 3.18-5
criu - update to 3.18-5
crit - update to 3.18-5
python3-criu - update to 3.18-5
IBM Cloud Pak for Watson AIOps - update to 4.4.0
libslirp - update to 4.4.0-1
libslirp-devel - update to 4.4.0-1
python3-podman - update to 4.6.0-1
podman (Red Hat package) - update to 4.6.1-5.el9
podman-docker - update to 4.6.1-8.0.1
podman - update to 4.6.1-8.0.1
podman-catatonit - update to 4.6.1-8.0.1
podman-tests - update to 4.6.1-8.0.1
podman-gvproxy - update to 4.6.1-8.0.1
podman-plugins - update to 4.6.1-8.0.1
podman-remote - update to 4.6.1-8.0.1
IBM Cloud Pak for Data Scheduling - update to 4.8.0
DB2 on Cloud Pak for Data - update to 4.8.2
DB2 Warehouse on Cloud Pak for Data - update to 4.8.2
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.8.2
openshift-clients (Red Hat package) - addressed in versions 4.14.0-202311031050.p0.g9b1e0d2.assembly.stream.el8, 4.14.0-202311031050.p0.g9b1e0d2.assembly.stream.el9, 4.14.0-202401111553.p0.g286cfa5.assembly.stream.el8, 4.14.0-202401111553.p0.g286cfa5.assembly.stream.el9
openshift (Red Hat package) - addressed in versions 4.14.0-202401121302.p0.ge36e183.assembly.stream.el8, 4.14.0-202401121302.p0.ge36e183.assembly.stream.el9
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.15.0
App Connect Enterprise Certified Container - addressed in versions 5.0.13, 10.1.1
kernel (Red Hat package) - update to 5.14.0-284.40.1.el9_2
kernel-rt (Red Hat package) - update to 5.14.0-284.40.1.rt14.325.el9_2
Red Hat Migration Toolkit for Applications - update to 6.2
Red Hat Satellite - update to 6.14
Dell EMC VxRail Appliance - update to 8.0.120
Storage Protect Server - update to 8.1.20
Operational Decision Manager - addressed in versions 8.10.5.1 Interim fix 49, 8.11.0.1 Interim fix 26, 8.12.0 Interim fix 8
IBM Sterling Order Management - update to 10.0.2403.1
Storage Protect Plus Container Agent - update to 10.1.12.7
Storage Protect Plus Server - update to 10.1.16.2
Azure Stack - update to 10.2402
Event Streams - update to 11.2.2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.25, 23.0.1.3
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.11, 23.0.10
ovn23.09 (Red Hat package) - update to 23.09.0-100.el9fdp
docker - update to 24.0.5-1
cockpit-podman - update to 75-1
IBM Observability with Instana - update to 266

External References

Related Security Bulletins