CVE-2024-45258

The req package before 3.43.4 for Go may send an unintended request when a malformed URL is provided, because cleanHost in http.go intentionally uses a "garbage in, garbage out" design.
Configurations

No configuration.

History

26 Aug 2024, 14:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-20

26 Aug 2024, 12:47

Type Values Removed Values Added
Summary
  • (es) El paquete req anterior a 3.43.4 para Go puede enviar una solicitud no deseada cuando se proporciona una URL con formato incorrecto, porque cleanHost en http.go utiliza intencionalmente un diseƱo de "basura que entra, basura sale".

25 Aug 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-25 22:15

Updated : 2024-08-26 14:35


NVD link : CVE-2024-45258

Mitre link : CVE-2024-45258

CVE.ORG link : CVE-2024-45258


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation