CVE-2020-15586
17.07.2020, 16:15
Go before 1.13.13 and 1.14.x before 1.14.5 has a data race in some net/http servers, as demonstrated by the httputil.ReverseProxy Handler, because it reads a request body and writes a response at the same time.
| Vendor | Product | Version |
|---|---|---|
| golang | go | 𝑥 < 1.13.13 |
| golang | go | 1.14.0 ≤ 𝑥 < 1.14.5 |
| cloudfoundry | cf-deployment | 𝑥 < 13.7.0 |
| cloudfoundry | routing-release | 𝑥 < 0.203.0 |
| debian | debian_linux | 9.0 |
| debian | debian_linux | 10.0 |
| opensuse | leap | 15.1 |
| opensuse | leap | 15.2 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| golang |
| ||||||||||||||||||||||||||
| golang-1.10 |
| ||||||||||||||||||||||||||
| golang-1.13 |
| ||||||||||||||||||||||||||
| golang-1.14 |
| ||||||||||||||||||||||||||
| golang-1.15 |
| ||||||||||||||||||||||||||
| golang-1.6 |
| ||||||||||||||||||||||||||
| golang-1.8 |
| ||||||||||||||||||||||||||
| golang-1.9 |
|
References