GHSA-3vp4-m3rf-835h

Suggest an improvement
Source
https://github.com/advisories/GHSA-3vp4-m3rf-835h
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/05/GHSA-3vp4-m3rf-835h/GHSA-3vp4-m3rf-835h.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-3vp4-m3rf-835h
Aliases
Published
2023-05-04T06:30:12Z
Modified
2023-11-08T04:11:58.943766Z
Severity
  • 5.6 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
Summary
Improper input validation in github.com/gin-gonic/gin
Details

Versions of the package github.com/gin-gonic/gin before version 1.9.0 are vulnerable to Improper Input Validation by allowing an attacker to use a specially crafted request via the X-Forwarded-Prefix header, potentially leading to cache poisoning.

Note: Although this issue does not pose a significant threat on its own it can serve as an input vector for other more impactful vulnerabilities. However, successful exploitation may depend on the server configuration and whether the header is used in the application logic.

Database specific
{
    "github_reviewed_at": "2023-05-05T02:20:00Z",
    "github_reviewed": true,
    "severity": "MODERATE",
    "nvd_published_at": "2023-05-04T05:15:09Z",
    "cwe_ids": [
        "CWE-20",
        "CWE-77"
    ]
}
References

Affected packages

Go / github.com/gin-gonic/gin

Package

Name
github.com/gin-gonic/gin
View open source insights on deps.dev
Purl
pkg:golang/github.com/gin-gonic/gin

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.9.0