VDB
BDU%3A2024-04486
BDU%3A2024-04486
PUBLISHED
CVSS 5.199999809265137 MEDIUM
Уязвимость компонента net-netip языка программирования Golang, связанная с неправильным контролем доступа, позволяющая нарушителю обойти существующую политику ограничения доступа
Risk Scores
CVSS 2.0
5.199999809265137
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Canonical Ltd., Novell Inc., Red Hat Inc., Сообщество свободного программного обеспечения, ООО «Ред Софт», The Go Project | Ubuntu, OpenSUSE Leap, Red Hat Enterprise Linux, Suse Linux Enterprise Server, SUSE Linux Enterprise Server for SAP Applications, SUSE Linux Enterprise Software Development Kit, openSUSE Tumbleweed, Red Hat Storage, Debian GNU/Linux, РЕД ОС (запись в едином реестре российских программ №3751), SUSE Linux Enterprise High Performance Computing, Red Hat Advanced Cluster Management for Kubernetes, Red Hat OpenShift Container Platform, Red Hat OpenStack Platform, SUSE Enterprise Storage, Red Hat Web Terminal, Node Maintenance Operator, OpenShift Developer Tools and Services, Red Hat Ceph Storage, Suse Linux Enterprise Desktop, Service Telemetry Framework, Node HealthCheck Operator, Migration Toolkit for Applications, Migration Toolkit for Virtualization, Red Hat OpenShift Virtualization, OpenShift Serverless, SUSE Linux Enterprise Module for Development Tools, Red Hat Developer Tools, Cryostat, Red Hat Advanced Cluster Security, Migration Toolkit for Containers, OpenShift Pipelines, SUSE Liberty Linux, SUSE Linux Enterprise Module for Containers, Go, Red Hat Ansible Automation Platform, Red Hat Satellite |
Timeline
- Jun 13, 2024 CVE Published
- Dec 5, 2024 CVE Updated
References
- https://go.dev/cl/590316 url
- https://go.dev/issue/67680 url
- https://groups.google.com/g/golang-announce/c/XbxouI9gY7k/m/TuoGEhxIEwAJ url
- https://pkg.go.dev/vuln/GO-2024-2887 url
- https://redos.red-soft.ru/support/secure/ url
- https://www.suse.com/security/cve/CVE-2024-24790.html url
- https://security-tracker.debian.org/tracker/CVE-2024-24790 url
- https://ubuntu.com/security/CVE-2024-24790 url
- https://access.redhat.com/security/cve/cve-2024-24790 url
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ advisory