Total vulnerabilities in the database
An issue was discovered in net/http in Go 1.11.5. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the second argument to http.NewRequest with \r\n followed by an HTTP header or a Redis command.
Software | From | Fixed in |
---|---|---|
golang / go | 1.11.5 | 1.11.5.x |
debian / debian_linux | 8.0 | 8.0.x |
debian / debian_linux | 9.0 | 9.0.x |
fedoraproject / fedora | 29 | 29.x |
redhat / enterprise_linux | 8.0 | 8.0.x |
redhat / developer_tools | 1.0 | 1.0.x |