Wind River Support Network

HomeDefectsLIN1018-4659
Fixed

LIN1018-4659 : Security Advisory - go - CVE-2019-14809

Created: Aug 13, 2019    Updated: Oct 23, 2022
Resolved Date: Oct 11, 2022
Found In Version: 10.18.44.1
Severity: Standard
Applicable for: Wind River Linux LTS 18
Component/s: Userspace

Description

net/url in Go before 1.11.13 and 1.12.x before 1.12.8 mishandles malformed hosts in URLs, leading to an authorization bypass in some applications. This is related to a Host field with a suffix appearing in neither Hostname() nor Port(), and is related to a non-numeric port number. For example, an attacker can compose a crafted javascript:// URL that results in a hostname of google.com.

CREATE(Triage): {Link=https://nvd.nist.gov/vuln/detail/CVE-2019-14809 User=admin}

CVEs


Live chat
Online