INFSA-2025:3772: go-toolset:rhel8 security update
Information about definition
Identificator: INFSA-2025:3772
Type: security
Release date: 2025-04-29 13:41:14 UTC
Information about package
Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang.
Vulnerabilities description
- CVE-2024-45336
A flaw was found in the net/http package of the Golang standard library. The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header redirected to b.com/ will not send that header to b.com. However, the sensitive headers would be restored if the client received a subsequent same-domain redirect. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.
- CVE-2024-45341
A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that applies to the certificate chain. Certificates containing URIs are not permitted in the web PKI, so this only affects users of private PKIs which make use of URIs.
Severity level
CVE | Score CVSS 2.0 | Score CVSS 3.x | Score CVSS 4.0 |
---|---|---|---|
NIST — CVE-2024-45336
|
no information | 5.9 | no information |
NIST — CVE-2024-45341
|
no information | 4.2 | no information |
Updated packages