#VU87198 Information disclosure in Go programming language - CVE-2023-45289
Published: March 7, 2024
Go programming language
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to insecure forwarding of headers and cookies to a third-party domains in net/http and net/http/cookiejar. A remote attacker can trick the application into sharing sensitive information with an attacker-controlled website.