Go before 1.15.15 and 1.16.x before 1.16.7 has a race condition that can lead to a net/http/httputil ReverseProxy panic upon an ErrAbortHandler abort.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
| AND |
|
History
21 Nov 2024, 06:13
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://cert-portal.siemens.com/productcert/pdf/ssa-222547.pdf - Patch, Third Party Advisory | |
| References | () https://groups.google.com/forum/#%21forum/golang-announce - | |
| References | () https://groups.google.com/g/golang-announce/c/JvWG9FUUYT0 - Mailing List, Third Party Advisory | |
| References | () https://groups.google.com/g/golang-announce/c/uHACNfXAZqk - Mailing List, Third Party Advisory | |
| References | () https://lists.debian.org/debian-lts-announce/2022/01/msg00016.html - Mailing List, Third Party Advisory | |
| References | () https://lists.debian.org/debian-lts-announce/2022/01/msg00017.html - Mailing List, Third Party Advisory | |
| References | () https://lists.debian.org/debian-lts-announce/2023/04/msg00021.html - | |
| References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2MU47VKTNXX33ZDLTI2ORRUY3KLJKU6G/ - | |
| References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HM7U5JNS5WU66Q3S26PFIU2ITB2ATTQ4/ - | |
| References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J4AMYYHGBYMIWCCR5RCDFI5RAUJOPO5L/ - | |
| References | () https://security.gentoo.org/glsa/202208-02 - Third Party Advisory | |
| References | () https://www.oracle.com/security-alerts/cpujan2022.html - Third Party Advisory |
20 Apr 2023, 00:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
14 Sep 2022, 21:11
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:h:siemens:scalance_lpe9403:-:*:*:*:*:*:*:* cpe:2.3:o:siemens:scalance_lpe9403_firmware:*:*:*:*:*:*:*:* |
|
| References | (GENTOO) https://security.gentoo.org/glsa/202208-02 - Third Party Advisory | |
| References | (CONFIRM) https://cert-portal.siemens.com/productcert/pdf/ssa-222547.pdf - Patch, Third Party Advisory |
04 Aug 2022, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
14 Jun 2022, 11:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
09 Feb 2022, 21:14
| Type | Values Removed | Values Added |
|---|---|---|
| References | (MISC) https://www.oracle.com/security-alerts/cpujan2022.html - Third Party Advisory | |
| References | (MLIST) https://lists.debian.org/debian-lts-announce/2022/01/msg00017.html - Mailing List, Third Party Advisory | |
| References | (MLIST) https://lists.debian.org/debian-lts-announce/2022/01/msg00016.html - Mailing List, Third Party Advisory | |
| CPE | cpe:2.3:a:oracle:timesten_in-memory_database:*:*:*:*:*:*:*:* cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
07 Feb 2022, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
22 Jan 2022, 00:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
02 Dec 2021, 20:37
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* |
|
| References | (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HM7U5JNS5WU66Q3S26PFIU2ITB2ATTQ4/ - Mailing List, Third Party Advisory | |
| References | (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2MU47VKTNXX33ZDLTI2ORRUY3KLJKU6G/ - Mailing List, Third Party Advisory |
25 Sep 2021, 01:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
22 Sep 2021, 18:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
16 Sep 2021, 13:09
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* | |
| References | (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/J4AMYYHGBYMIWCCR5RCDFI5RAUJOPO5L/ - Mailing List, Third Party Advisory |
16 Sep 2021, 01:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
19 Aug 2021, 15:03
| Type | Values Removed | Values Added |
|---|---|---|
| References | (MISC) https://groups.google.com/forum/#!forum/golang-announce - Mailing List, Release Notes, Third Party Advisory | |
| References | (MISC) https://groups.google.com/g/golang-announce/c/uHACNfXAZqk - Mailing List, Third Party Advisory | |
| References | (MISC) https://groups.google.com/g/golang-announce/c/JvWG9FUUYT0 - Mailing List, Third Party Advisory | |
| CVSS |
v2 : v3 : |
v2 : 4.3
v3 : 5.9 |
| CWE | CWE-362 | |
| CPE | cpe:2.3:a:golang:go:*:*:*:*:*:*:*:* |
08 Aug 2021, 06:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2021-08-08 06:15
Updated : 2024-11-21 06:13
NVD link : CVE-2021-36221
Mitre link : CVE-2021-36221
CVE.ORG link : CVE-2021-36221
JSON object : View
Products Affected
golang
- go
siemens
- scalance_lpe9403
- scalance_lpe9403_firmware
debian
- debian_linux
oracle
- timesten_in-memory_database
fedoraproject
- fedora
CWE
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
