VDB
RHSA-2022:6188
RHSA-2022:6188
PUBLISHED
CVSS 6.5 MEDIUM
A flaw was found in golang. The HTTP/1 client accepted invalid Transfer-Encoding headers indicating "chunked" encoding. This issue could allow request smuggling, but only if combined with an intermediate server that also improperly accepts the header as invalid.
Risk Scores
CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | workload-availability/node-maintenance-rhel8-operator@sha256:f7bd1a3a87b0524660b0107b495e66fe8697833a7d7a9b2b03e94f4f8a164d90_amd64 as a component of Node Maintenance Operator 4.11 for RHEL 8 | *, *, * |
| Red Hat | workload-availability/node-maintenance-must-gather-rhel8@sha256:ac27a268a9860dbd5a5bc72e1d4c8be08107be76cbbcfc83b77db67c10fb2a15_amd64 as a component of Node Maintenance Operator 4.11 for RHEL 8 | *, *, workload-availability/node-maintenance-must-gather-rhel8@sha256:ac27a268a9860dbd5a5bc72e1d4c8be08107be76cbbcfc83b77db67c10fb2a15_amd64 |
| Red Hat | workload-availability/node-maintenance-rhel8-operator@sha256:f7bd1a3a87b0524660b0107b495e66fe8697833a7d7a9b2b03e94f4f8a164d90_amd64 as a component of Node Maintenance Operator 4.11 for RHEL 8 | *, workload-availability/node-maintenance-rhel8-operator@sha256:f7bd1a3a87b0524660b0107b495e66fe8697833a7d7a9b2b03e94f4f8a164d90_amd64, workload-availability/node-maintenance-rhel8-operator@sha256:f7bd1a3a87b0524660b0107b495e66fe8697833a7d7a9b2b03e94f4f8a164d90_amd64 |
| Red Hat | workload-availability/node-maintenance-operator-bundle@sha256:fffb33c8f94a53a1b55bc23be12d8469e280ecbf5fa43057c5618d0f9dfb2d45_amd64 as a component of Node Maintenance Operator 4.11 for RHEL 8 | workload-availability/node-maintenance-operator-bundle@sha256:fffb33c8f94a53a1b55bc23be12d8469e280ecbf5fa43057c5618d0f9dfb2d45_amd64, *, * |
| Red Hat | workload-availability/node-maintenance-rhel8-operator@sha256:f7bd1a3a87b0524660b0107b495e66fe8697833a7d7a9b2b03e94f4f8a164d90_amd64 | |
| Red Hat | workload-availability/node-maintenance-must-gather-rhel8@sha256:ac27a268a9860dbd5a5bc72e1d4c8be08107be76cbbcfc83b77db67c10fb2a15_amd64 as a component of Node Maintenance Operator 4.11 for RHEL 8 | workload-availability/node-maintenance-must-gather-rhel8@sha256:ac27a268a9860dbd5a5bc72e1d4c8be08107be76cbbcfc83b77db67c10fb2a15_amd64, *, workload-availability/node-maintenance-must-gather-rhel8@sha256:ac27a268a9860dbd5a5bc72e1d4c8be08107be76cbbcfc83b77db67c10fb2a15_amd64 |
| Red Hat | workload-availability/node-maintenance-operator-bundle@sha256:fffb33c8f94a53a1b55bc23be12d8469e280ecbf5fa43057c5618d0f9dfb2d45_amd64 as a component of Node Maintenance Operator 4.11 for RHEL 8 | *, workload-availability/node-maintenance-operator-bundle@sha256:fffb33c8f94a53a1b55bc23be12d8469e280ecbf5fa43057c5618d0f9dfb2d45_amd64, workload-availability/node-maintenance-operator-bundle@sha256:fffb33c8f94a53a1b55bc23be12d8469e280ecbf5fa43057c5618d0f9dfb2d45_amd64 |
Timeline
- Aug 25, 2022 CVE Published
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 26, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 2, 2026 Security Advisory
- May 5, 2026 Security Advisory
- May 16, 2026 Security Advisory
References
- https://bugzilla.redhat.com/show_bug.cgi?id=2107376 issue
- https://go.dev/issue/53415 advisory
- https://access.redhat.com/errata/RHSA-2022:6188 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2107371 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2107386 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_6188.json advisory
- https://www.cve.org/CVERecord?id=CVE-2022-28131 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-30631 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2107392 issue
- https://nvd.nist.gov/vuln/detail/CVE-2022-28131 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2107374 issue
- https://www.cve.org/CVERecord?id=CVE-2022-30632 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2107342 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2107383 issue
- https://access.redhat.com/security/cve/CVE-2022-30630 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-30630 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-30633 advisory
- https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-32148 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
…and 24 more