VDB
BDU%3A2023-01943
BDU%3A2023-01943
PUBLISHED
CVSS 7.5 HIGH
Уязвимость библиотек net/http и mime/multipart средства разработки GoLang, используемых в прикладном программном обеспечении ППО "Аврора Центр", позволяющая нарушителю выполнить атаку типа "отказ в обслуживании
Risk Scores
CVSS 2.0
7.5
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat Inc., Novell Inc., Сообщество свободного программного обеспечения, ООО «Ред Софт», The Go Project, ООО «Открытая мобильная платформа» | Red Hat Enterprise Linux, SUSE Linux Enterprise Server for SAP Applications, Debian GNU/Linux, openSUSE Tumbleweed, Red Hat Storage, OpenShift Container Platform, Red Hat Quay, SUSE CaaS Platform, Suse Linux Enterprise Server, SUSE Linux Enterprise High Performance Computing, РЕД ОС (запись в едином реестре российских программ №3751), OpenSUSE Leap, Ansible Automation Platform, Red Hat Openshift Data Foundation, SUSE Enterprise Storage, Red Hat Advanced Cluster Management for Kubernetes, Suse Linux Enterprise Desktop, Red Hat Migration Toolkit for Containers, Red Hat OpenStack Platform, SUSE Manager Retail Branch Server, SUSE Manager Proxy, SUSE Manager Server, SUSE Linux Enterprise Module for Development Tools, Node Maintenance Operator, Service Telemetry Framework, Application Interconnect, OpenShift Developer Tools and Services, SUSE Linux Enterprise Real Time, Red Hat Ceph Storage, Go, Аврора Центр (запись в едином реестре российских программ №6875), Red Hat OpenShift on AWS, Red Hat OpenShift Data Science (RHODS), Openshift Service Mesh, OADP-1.1-RHEL-8, Node HealthCheck Operator, Network Observability Operator, Migration Toolkit for Applications, Migration Toolkit for Virtualization, Red Hat OpenShift Virtualization, OpenShift Serverless, SUSE Linux Enterprise Module for Containers |
Timeline
- Apr 11, 2023 CVE Published
- Apr 22, 2024 CVE Updated
References
- https://go.dev/issue/58006 url
- https://security-tracker.debian.org/tracker/CVE-2022-41725 url
- https://groups.google.com/g/golang-announce/c/V0aBFqaFs_E url
- https://pkg.go.dev/vuln/GO-2023-1569 url
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ url
- https://go.dev/cl/468124 advisory
- https://www.suse.com/security/cve/CVE-2022-41725.html advisory
- https://access.redhat.com/security/cve/CVE-2022-41725 advisory