Improper Neutralization of HTTP Headers for Scripting Syntax in Go programming language - CVE-2023-29406
Published: July 17, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to improper input validation in HTTP/1 client when handling HTTP Host header. A remote non-authenticated attacker can send a specially crafted HTTP request with a maliciously crafted Host header and inject additional headers or entire requests.
Successful exploitation of the vulnerability may allow an attacker to perform cross-site scripting, cache poisoning or session hijacking attacks.
Affected software
Amazon Linux AMI
Gentoo Linux
Oracle Linux
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
Fedora
Anolis OS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Development Tools Module
openSUSE Leap
Ubuntu
openEuler
Red Hat OpenShift Serverless
OpenShift Data Foundation (formerly OpenShift Container Storage)
Run Once Duration Override Operator for Red Hat OpenShift
Service Telemetry Framework
Consul Enterprise
Cryostat
IBM Spectrum Copy Data Management
Red Hat OpenShift distributed tracing (RHOSDT)
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Red Hat Advanced Cluster Security for Kubernetes
OpenShift Logging
Red Hat OpenStack
Operations Dashboard
Automation Assets in IBM Cloud Pak for Integration (CP4I)
IBM Cloud Transformation Advisor
IBM Cloud Pak for Data Scheduling
IBM Watson Discovery for IBM Cloud Pak for Data
App Connect Enterprise Certified Container
Red Hat Migration Toolkit for Applications
Red Hat Satellite
Azure Stack
IBM Cloud Pak for Business Automation
IBM Observability with Instana
OpenShift API for Data Protection (OADP)
Secondary Scheduler Operator for Red Hat OpenShift (OSSO)
Network Observability plugin for the Openshift Console
Migration Toolkit for Containers
OpenShift Serverless Client
IBM Cloud Pak for Multicloud Management
Red Hat OpenShift Container Platform
IBM Business Automation Manager Open Editions
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
ObjectScale
Cloud Pak for Network Automation
IBM Cloud Pak for Watson AIOps
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
Storage Protect Server
IBM Sterling Order Management
Storage Protect Plus Container Agent
Storage Protect Plus Server
Robotic Process Automation for Cloud Pak
Splunk Enterprise
golang-1.18-src (Ubuntu package)
golang-1.18-go (Ubuntu package)
golang-1.18 (Ubuntu package)
toolbox-tests
toolbox
toolbox (Red Hat package)
udica
amazon-ecr-credential-helper
nerdctl
runc
cni-plugins
slirp4netns
oci-seccomp-bpf-hook
containernetworking-plugins (Red Hat package)
containernetworking-plugins
python-octavia-tests-tempest (Red Hat package)
containerd
skopeo-debuginfo
containers-common
skopeo
skopeo-debugsource
aardvark-dns
netavark
crun
openshift-serverless-clients (Red Hat package)
fuse-overlayfs
skopeo (Red Hat package)
skopeo-tests
golang
golang-devel
golang-help
golang-1.17-go (Ubuntu package)
golang-1.17 (Ubuntu package)
golang-1.17-src (Ubuntu package)
go1.19-race
go1.19-doc
go1.19
go1.19-openssl-doc
go1.19-openssl
go1.19-openssl-race
go1.20-openssl-race
go1.20-openssl-doc
go1.20-openssl
go1.20-openssl-debuginfo
go1.20
go1.20-doc
go1.20-race
go1.20-debuginfo
golang-bin
golang-shared
golang-docs
golang-misc
golang-src
golang-tests
dev-lang/go
cri-o (Red Hat package)
buildah
buildah-tests
buildah (Red Hat package)
ecs-init
conmon
container-selinux
container-selinux (Red Hat package)
amazon-ssm-agent
etcd (Red Hat package)
etcd
etcdctl
criu-libs
criu-devel
criu
crit
python3-criu
libslirp
libslirp-devel
python3-podman
podman (Red Hat package)
podman-docker
podman
podman-catatonit
podman-tests
podman-gvproxy
podman-plugins
podman-remote
openshift-clients (Red Hat package)
openshift (Red Hat package)
kernel (Red Hat package)
kernel-rt (Red Hat package)
ovn23.09 (Red Hat package)
docker
cockpit-podman
IBM Cloud Pak System
Dell EMC VxRail Appliance
Operational Decision Manager
Event Streams
How to mitigate CVE-2023-29406
Red Hat OpenShift Serverless - update to 1.30.2
Run Once Duration Override Operator for Red Hat OpenShift - update to 1.0.1
Secondary Scheduler Operator for Red Hat OpenShift (OSSO) - update to 1.1.3
Service Telemetry Framework - update to 1.5.2
Migration Toolkit for Containers - update to 1.7.14
Consul Enterprise - addressed in versions 1.14.9, 1.15.5, 1.16.1
OpenShift Serverless Client - update to 1.30.2
IBM Spectrum Copy Data Management - update to 2.2.21.0
IBM Cloud Pak for Multicloud Management - update to 2.3.8
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.0
Red Hat Advanced Cluster Security for Kubernetes - update to 4.4.0
Red Hat OpenShift Container Platform - addressed in versions 4.12.45, 4.13.22, 4.13.24, 4.14.2, 4.14.4
OpenShift Logging - addressed in versions 5.6.12, 5.7.7
IBM Business Automation Manager Open Editions - update to 9.0.1
Splunk Enterprise - addressed in versions 9.0.8, 9.1.3
Red Hat OpenStack - update to 16.2.5
Operations Dashboard - update to 2022.2.1-14-lts
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - addressed in versions 2022.2.1-12, 2023.2.1-2
Automation Assets in IBM Cloud Pak for Integration (CP4I) - update to 2022.2.1-11
golang-1.18-src (Ubuntu package) - addressed in versions Ubuntu Pro, 1.18.1-1ubuntu1.2, 1.18.1-1ubuntu1~20.04.3
golang-1.18-go (Ubuntu package) - addressed in versions Ubuntu Pro, 1.18.1-1ubuntu1.2, 1.18.1-1ubuntu1~20.04.3
golang-1.18 (Ubuntu package) - addressed in versions Ubuntu Pro, 1.18.1-1ubuntu1.2, 1.18.1-1ubuntu1~20.04.3
toolbox-tests - update to 0.0.99.4-5.0.1
toolbox - update to 0.0.99.4-5.0.1
toolbox (Red Hat package) - update to 0.0.99.4-6.el9_3
udica - update to 0.2.6-20
amazon-ecr-credential-helper - update to 0.7.1-2
nerdctl - update to 1.1.0-1
runc - update to 1.1.7-1
runc - update to 1.1.12-1.0.1
cni-plugins - update to 1.2.0-1
slirp4netns - update to 1.2.1-1
oci-seccomp-bpf-hook - update to 1.2.9-1
containernetworking-plugins (Red Hat package) - update to 1.3.0-4.el9
containernetworking-plugins - update to 1.3.0-8.0.1
ObjectScale - update to 1.4.0
python-octavia-tests-tempest (Red Hat package) - update to 1.4.1-2.20230111145026.f7718ef.el8ost
containerd - addressed in versions 1.4.13-5, 1.7.2-1
skopeo-debuginfo - addressed in versions 1.5.2-6, 1.5.2-7, 1.8.0-5
containers-common - addressed in versions 1.5.2-6, 1.5.2-7
skopeo - addressed in versions 1.5.2-6, 1.5.2-7, 1.8.0-5
skopeo-debugsource - addressed in versions 1.5.2-6, 1.5.2-7, 1.8.0-5
aardvark-dns - update to 1.7.0-2.0.1
netavark - update to 1.7.0-2.0.1
crun - update to 1.8.7-1
openshift-serverless-clients (Red Hat package) - update to 1.9.2-4.el8
fuse-overlayfs - update to 1.12-1.0.1
skopeo (Red Hat package) - update to 1.13.3-1.el9
skopeo - update to 1.13.3-3.0.1
skopeo-tests - update to 1.13.3-3.0.1
golang - addressed in versions 1.15.7-31, 1.17.3-20
golang-devel - addressed in versions 1.15.7-31, 1.17.3-20
golang-help - addressed in versions 1.15.7-31, 1.17.3-20
golang-1.17-go (Ubuntu package) - update to 1.17.13-3ubuntu1.2
golang-1.17 (Ubuntu package) - update to 1.17.13-3ubuntu1.2
golang-1.17-src (Ubuntu package) - update to 1.17.13-3ubuntu1.2
go1.19-race - update to 1.19.11-150000.1.37.1
go1.19-doc - update to 1.19.11-150000.1.37.1
go1.19 - update to 1.19.11-150000.1.37.1
golang - update to 1.19.13-1.el7
go1.19-openssl-doc - update to 1.19.13.1-150000.1.8.1
go1.19-openssl - update to 1.19.13.1-150000.1.8.1
go1.19-openssl-race - update to 1.19.13.1-150000.1.8.1
golang - addressed in versions 1.20.6-1, 1.20.8-1.47
go1.20-openssl-race - update to 1.20.6.1-150000.1.8.1
go1.20-openssl-doc - update to 1.20.6.1-150000.1.8.1
go1.20-openssl - update to 1.20.6.1-150000.1.8.1
go1.20-openssl-debuginfo - update to 1.20.6.1-150000.1.8.1
go1.20 - update to 1.20.6-150000.1.17.1
go1.20-doc - update to 1.20.6-150000.1.17.1
go1.20-race - update to 1.20.6-150000.1.17.1
go1.20-debuginfo - update to 1.20.6-150000.1.17.1
golang - update to 1.20.9-1
golang-bin - update to 1.20.9-1
golang-shared - update to 1.20.9-1
golang-docs - update to 1.20.9-1
golang-misc - update to 1.20.9-1
golang-src - update to 1.20.9-1
golang-tests - update to 1.20.9-1
dev-lang/go - update to 1.20.10
cri-o (Red Hat package) - addressed in versions 1.27.1-13.1.rhaos4.14.git956c5f7.el8, 1.27.1-13.1.rhaos4.14.git956c5f7.el9, 1.27.3-2.rhaos4.14.git03502b6.el8, 1.27.3-2.rhaos4.14.git03502b6.el9
buildah - update to 1.31.3-1
buildah-tests - update to 1.31.3-1
buildah (Red Hat package) - update to 1.31.3-1.el9
containers-common - update to 1-71.0.1
ecs-init - update to 1.75.0-1
conmon - update to 2.1.8-1
IBM Cloud Pak System - update to 2.3.3.6 iFix 1
Cloud Pak for Network Automation - update to 2.7
container-selinux - update to 2.221.0-1
container-selinux (Red Hat package) - addressed in versions 2.223.0-1.rhaos4.14.el8, 2.223.0-2.rhaos4.14.el9
amazon-ssm-agent - update to 3.2.1630.0-1
etcd (Red Hat package) - update to 3.3.23-15.el8ost
etcd - update to 3.4.14-11
etcd - update to 3.5.12-150000.7.6.1
etcdctl - update to 3.5.12-150000.7.6.1
IBM Cloud Transformation Advisor - update to 3.7.0
criu-libs - update to 3.18-5
criu-devel - update to 3.18-5
criu - update to 3.18-5
crit - update to 3.18-5
python3-criu - update to 3.18-5
IBM Cloud Pak for Watson AIOps - update to 4.4.0
libslirp - update to 4.4.0-1
libslirp-devel - update to 4.4.0-1
python3-podman - update to 4.6.0-1
podman (Red Hat package) - update to 4.6.1-5.el9
podman-docker - update to 4.6.1-8.0.1
podman - update to 4.6.1-8.0.1
podman-catatonit - update to 4.6.1-8.0.1
podman-tests - update to 4.6.1-8.0.1
podman-gvproxy - update to 4.6.1-8.0.1
podman-plugins - update to 4.6.1-8.0.1
podman-remote - update to 4.6.1-8.0.1
IBM Cloud Pak for Data Scheduling - update to 4.8.0
DB2 on Cloud Pak for Data - update to 4.8.2
DB2 Warehouse on Cloud Pak for Data - update to 4.8.2
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.8.2
openshift-clients (Red Hat package) - addressed in versions 4.14.0-202311031050.p0.g9b1e0d2.assembly.stream.el8, 4.14.0-202311031050.p0.g9b1e0d2.assembly.stream.el9, 4.14.0-202401111553.p0.g286cfa5.assembly.stream.el8, 4.14.0-202401111553.p0.g286cfa5.assembly.stream.el9
openshift (Red Hat package) - addressed in versions 4.14.0-202401121302.p0.ge36e183.assembly.stream.el8, 4.14.0-202401121302.p0.ge36e183.assembly.stream.el9
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.15.0
App Connect Enterprise Certified Container - addressed in versions 5.0.13, 10.1.1
kernel (Red Hat package) - update to 5.14.0-284.40.1.el9_2
kernel-rt (Red Hat package) - update to 5.14.0-284.40.1.rt14.325.el9_2
Red Hat Migration Toolkit for Applications - update to 6.2
Red Hat Satellite - update to 6.14
Dell EMC VxRail Appliance - update to 8.0.120
Storage Protect Server - update to 8.1.20
Operational Decision Manager - addressed in versions 8.10.5.1 Interim fix 49, 8.11.0.1 Interim fix 26, 8.12.0 Interim fix 8
IBM Sterling Order Management - update to 10.0.2403.1
Storage Protect Plus Container Agent - update to 10.1.12.7
Storage Protect Plus Server - update to 10.1.16.2
Azure Stack - update to 10.2402
Event Streams - update to 11.2.2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.25, 23.0.1.3
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.11, 23.0.10
ovn23.09 (Red Hat package) - update to 23.09.0-100.el9fdp
docker - update to 24.0.5-1
cockpit-podman - update to 75-1
IBM Observability with Instana - update to 266
External References
Related Security Bulletins
- HTTP Host header injection in Go programming language
- SUSE update for go1.20
- SUSE update for go1.19
- SUSE update for go1.20-openssl
- Improper neutralization of HTTP headers for scripting syntax in IBM Event Streams
- Multiple vulnerabilities in Consul Enterprise
- Multiple vulnerabilities in IBM Spectrum Copy Data Management
- Multiple vulnerabilities in IBM Storage Protect Server
- SUSE update for go1.19-openssl
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Amazon Linux AMI update for golang
- Amazon Linux AMI update for containerd
- Multiple vulnerabilities in Red Hat OpenStack Platform 16.2
- Multiple vulnerabilities in Logging Subsystem 5.6 for Red Hat OpenShift
- Multiple vulnerabilities in Logging Subsystem 5.7 for Red Hat OpenShift
- Multiple vulnerabilities in Service Telemetry Framework 1.5
- Multiple vulnerabilities in Network Observability plugin for the Openshift Console
- Multiple vulnerabilities in Red Hat OpenStack Platform 16.2
- Fedora EPEL 7 update for golang
- Multiple vulnerabilities in Cryostat 2 on RHEL 8
- Multiple vulnerabilities in Red Hat Openshift distributed tracing
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.1
- Multiple vulnerabilities in Red Hat Migration Toolkit for Containers (MTC) 1.7
- Improper neutralization of HTTP headers for scripting syntax in Operations Dashboard
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Multiple vulnerabilities in IBM Cloud Pak System
- Red Hat Enterprise Linux 9 update for podman
- Red Hat Enterprise Linux 9 update for buildah
- Red Hat Enterprise Linux 9 update for containernetworking-plugins
- Red Hat Enterprise Linux 9 update for skopeo
- Red Hat Enterprise Linux 9 update for toolbox
- Multiple vulnerabilities in Secondary Scheduler Operator for Red Hat OpenShift 1.1
- Multiple vulnerabilities in Run Once Duration Override Operator for Red Hat OpenShift
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- Multiple vulnerabilities in Red Hat OpenShift Serverless Client
- Improper neutralization of HTTP headers for scripting syntax in Platform Navigator and Automation Assets in IBM Cloud Pak for Integration
- Multiple vulnerabilities in IBM Business Automation Manager Open Editions
- Multiple vulnerabilities in Oracle Linux
- Red Hat Enterprise Linux 8 update for the container-tools:rhel8 module
- Red Hat Enterprise Linux 8 update for the container-tools:4.0 module
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Red Hat Enterprise Linux 8 update for the container-tools:4.0 module
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Gentoo update for Go
- Multiple vulnerabilities in Red Hat Satellite 6.14
- IBM App Connect Enterprise Certified Container update for Go
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- IBM Cloud Pak for Data Scheduling update for Go
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in IBM Operational Decision Manager
- Splunk Enterprise update for third-party components
- OpenShift Container Platform 4.14 update for golang
- Multiple vulnerabilities in IBM Watson Discovery
- Multiple vulnerabilities in IBM Observability with Instana
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data
- Multiple vulnerabilities in IBM Cloud Pak for Multicloud Management
- Multiple vulnerabilities in Red Hat Migration Toolkit for Applications
- Multiple vulnerabilities in IBM Cloud Pak for Network Automation
- openEuler 22.03 LTS SP1 update for golang
- openEuler 22.03 LTS SP2 update for golang
- openEuler 20.03 LTS SP1 update for golang
- openEuler 20.03 LTS SP3 update for golang
- openEuler 22.03 LTS update for golang
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation 4.15
- Multiple vulnerabilities in IBM Cloud Pak for AIOps
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.4
- Multiple vulnerabilities in IBM Sterling Order Management
- openEuler 22.03 LTS SP1 update for skopeo
- openEuler 22.03 LTS SP2 update for skopeo
- openEuler 22.03 LTS update for skopeo
- Multiple vulnerabilities in IBM Storage Protect Plus Container Agent
- openEuler 22.03 LTS SP3 update for skopeo
- Multiple vulnerabilities in Dell APEX Cloud Platform for Microsoft Azure and Dell APEX Cloud Platform Foundation Software
- Multiple vulnerabilities in Dell EMC VxRail Appliance
- Amazon Linux AMI update for ecs-init
- Multiple vulnerabilities in Dell ObjectScale
- Multiple vulnerabilities in Storage Protect Plus Server
- SUSE update for etcd
- Ubuntu update for golang-1.18
- Ubuntu update for golang-1.17
- Amazon Linux AMI update for golang
- Amazon Linux AMI update for nerdctl
- Amazon Linux AMI update for containerd
- Amazon Linux AMI update for runc
- Amazon Linux AMI update for cni-plugins
- Amazon Linux AMI update for docker
- Amazon Linux AMI update for oci-add-hooks
- Amazon Linux AMI update for amazon-ecr-credential-helper
- Amazon Linux AMI update for amazon-ssm-agent
- openEuler 20.03 LTS SP4 update for etcd
- Anolis OS update for golang
- Anolis OS update for container-tools:an8 module