Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 948232 (CVE-2024-45336, CVE-2024-45341) - <dev-lang/go-1.22.11, <dev-lang/go-1.23.5: multiple vulnerabilities
Summary: <dev-lang/go-1.22.11, <dev-lang/go-1.23.5: multiple vulnerabilities
Status: CONFIRMED
Alias: CVE-2024-45336, CVE-2024-45341
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal
Assignee: Gentoo Security
URL:
Whiteboard: B3 [glsa?]
Keywords:
Depends on: 948231
Blocks:
  Show dependency tree
 
Reported: 2025-01-17 16:16 UTC by William Hubbs
Modified: 2025-03-20 20:37 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description William Hubbs gentoo-dev 2025-01-17 16:16:29 UTC
crypto/x509: usage of IPv6 zone IDs can bypass URI name constraints

A certificate with a URI which has a IPv6 address with a zone ID may
incorrectly satisfy a URI name constraint that applies to the
certificate
chain.

Certificates containing URIs are not permitted in the web PKI, so this
only affects users of private PKIs which make use of URIs.

Thanks to Juho Forsén of Mattermost for reporting this issue.

This is CVE-2024-45341 and Go issue https://go.dev/issue/71156.

net/http: sensitive headers incorrectly sent after cross-domain redirect

The HTTP client drops sensitive headers after following a cross-domain
redirect.
For example, a request to a.com/ containing an Authorization header
which is
redirected to b.com/ will not send that header to b.com.

In the event that the client received a subsequent same-domain redirect,
however,
the sensitive headers would be restored. For example, a chain of
redirects from
a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the
Authorization
header to b.com/2.

Thanks to Kyle Seely for reporting this issue.

This is CVE-2024-45336 and Go issue https://go.dev/issue/70530.