VDB
RHSA-2022%3A6187
RHSA-2022%3A6187
PUBLISHED
CVSS 6.5 MEDIUM
A flaw was found in golang. The HTTP/1 client accepted invalid Transfer-Encoding headers indicating "chunked" encoding. This issue could allow request smuggling, but only if combined with an intermediate server that also improperly accepts the header as invalid.
Risk Scores
CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | workload-availability/node-healthcheck-rhel8-operator@sha256:3ce6b1557d00691dbaa869a1efe36098dc0b764196141d7777b82f355b35b8e3_amd64 as a component of Node Healthcheck Operator 0.3 for RHEL 8 | workload-availability/node-healthcheck-rhel8-operator@sha256:3ce6b1557d00691dbaa869a1efe36098dc0b764196141d7777b82f355b35b8e3_amd64, workload-availability/node-healthcheck-rhel8-operator@sha256:3ce6b1557d00691dbaa869a1efe36098dc0b764196141d7777b82f355b35b8e3_amd64, workload-availability/node-healthcheck-rhel8-operator@sha256:3ce6b1557d00691dbaa869a1efe36098dc0b764196141d7777b82f355b35b8e3_amd64 |
| Red Hat | workload-availability/node-healthcheck-operator-bundle@sha256:8223bda16ac5ffac4b7407c849c4c30ee006ddafd34cad8a03d2af8314d56f58_amd64 as a component of Node Healthcheck Operator 0.3 for RHEL 8 | workload-availability/node-healthcheck-operator-bundle@sha256:8223bda16ac5ffac4b7407c849c4c30ee006ddafd34cad8a03d2af8314d56f58_amd64, workload-availability/node-healthcheck-operator-bundle@sha256:8223bda16ac5ffac4b7407c849c4c30ee006ddafd34cad8a03d2af8314d56f58_amd64, workload-availability/node-healthcheck-operator-bundle@sha256:8223bda16ac5ffac4b7407c849c4c30ee006ddafd34cad8a03d2af8314d56f58_amd64 |
| golang | go | |
| golang | Go | |
| Red Hat | workload-availability/node-healthcheck-rhel8-operator@sha256:3ce6b1557d00691dbaa869a1efe36098dc0b764196141d7777b82f355b35b8e3_amd64 as a component of Node Healthcheck Operator 0.3 for RHEL 8 | *, *, * |
| Red Hat | workload-availability/node-healthcheck-operator-bundle@sha256:8223bda16ac5ffac4b7407c849c4c30ee006ddafd34cad8a03d2af8314d56f58_amd64 as a component of Node Healthcheck Operator 0.3 for RHEL 8 | *, workload-availability/node-healthcheck-operator-bundle@sha256:8223bda16ac5ffac4b7407c849c4c30ee006ddafd34cad8a03d2af8314d56f58_amd64, workload-availability/node-healthcheck-operator-bundle@sha256:8223bda16ac5ffac4b7407c849c4c30ee006ddafd34cad8a03d2af8314d56f58_amd64 |
Timeline
- Aug 25, 2022 CVE Published
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Jun 19, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2022:6187 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2077689 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2107342 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2107374 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_6187.json advisory
- https://access.redhat.com/security/cve/CVE-2022-1705 advisory
- https://www.cve.org/CVERecord?id=CVE-2022-1705 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-1705 advisory
- https://go.dev/issue/53188 advisory
- https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE advisory
- https://access.redhat.com/security/cve/CVE-2022-28327 advisory
- https://www.cve.org/CVERecord?id=CVE-2022-28327 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-28327 advisory
- https://groups.google.com/g/golang-announce/c/oecdBNLOml8 advisory
- https://access.redhat.com/security/cve/CVE-2022-30631 advisory
- https://www.cve.org/CVERecord?id=CVE-2022-30631 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-30631 advisory
- https://go.dev/issue/53168 advisory