l3montree-dev / devguard

DevGuard Backend - Manage your CVEs seamlessly, Integrate your Vulnerability Scanners, Security Framework Documentation made easy, Compliance to security Frameworks - OWASP Incubating Project
https://devguard.org/
Other
44 stars 5 forks source link

CVE-2024-24791 #150

Closed devguard-app[bot] closed 3 months ago

devguard-app[bot] commented 3 months ago

CVE-2024-24791

The net/http HTTP/1.1 client mishandled the case where a server responds to a request with an "Expect: 100-continue" header with a non-informational (200 or higher) status. This mishandling could leave a client connection in an invalid state, where the next request sent on the connection will fail. An attacker sending a request to a net/http/httputil.ReverseProxy proxy can exploit this mishandling to cause a denial of service by sending "Expect: 100-continue" requests which elicit a non-informational response from the backend. Each such request leaves the proxy with an invalid connection, and causes one subsequent request using that connection to fail.

Affected component

The vulnerability is in pkg:golang/stdlib@1.22.3, detected by the container-scanning scan.

Recommended fix

Upgrade to version 1.22.5 or later.

Risk: 3.45 (Low)

EPSS: 0.04 %

The exploit probability is very low. The vulnerability is unlikely to be exploited in the next 30 days.

Exploit: Not available

We did not find any exploit available. Neither in GitHub repositories nor in the Exploit-Database. There are no script kiddies exploiting this vulnerability.

Vulnerability Depth: 1

The vulnerability is in a direct dependency of your project.

CVSS-BE: 7.5

CVSS-B: 7.5

More details can be found in DevGuard


We need to fix this.

timbastin commented 3 months ago

Test

timbastin commented 3 months ago

Wow direkt aus GitHub

timbastin commented 3 months ago

/accept Dieses Risiko ist in Ordnung.

timbastin commented 3 months ago

/reopen Müssen wir doch fixen

timbastin commented 3 months ago

/a Ein alias

timbastin commented 3 months ago

/r Müssen wir doch leider fixen

devguard-app[bot] commented 3 months ago

Tim Bastin commented on the flaw

Noch ein Versuch

devguard-app[bot] commented 3 months ago

Tim Bastin accepted the flaw

Kann ich auch accepten?

devguard-app[bot] commented 3 months ago

Tim Bastin reopened the flaw

Ich möchte es reopen

devguard-app[bot] commented 3 months ago

Tim Bastin marked the flaw as false positive

Das ist ein False-Positive

timbastin commented 3 months ago

/r Reopen flaw

timbastin commented 3 months ago

/r Reopen

timbastin commented 3 months ago

/r Reopen

timbastin commented 3 months ago

/r Test

timbastin commented 3 months ago

/a Accept this risk