Vulnerability Report: GO-2023-1526
- CVE-2023-24623, GHSA-v9mp-j8g7-2q6m
- Affects: github.com/hakobe/paranoidhttp
- Published: Feb 14, 2023
- Modified: Jun 12, 2023
Paranoidhttp before is vulnerable to SSRF because [::] is equivalent to the 127.0.0.1 address, but does not match the filter for private addresses.
Affected Packages
-
PathVersionsSymbols
-
before v0.3.0all symbols
Aliases
References
- https://github.com/hakobe/paranoidhttp/blob/master/CHANGELOG.md#v030-2023-01-19
- https://github.com/hakobe/paranoidhttp/commit/07f671da14ce63a80f4e52432b32e8d178d75fd3
- https://github.com/hakobe/paranoidhttp/compare/v0.2.0...v0.3.0
- https://vuln.go.dev/ID/GO-2023-1526.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.