Versio.io

CVE-2019-16276

Common vulnerabilities & exposures (CVE)

CVE databaseCVE database blogpostRelease & EoL database
 
Published at: - 25-09-2019 02:00
Last modified: - 25-09-2019 02:00
Total changes: - 170

Description

CVE-2019-16276 golang: HTTP/1.1 headers with a space before the colon leads to filter bypass or request smuggling

Common Vulnerability Scoring System (CVSS)

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Low
Attack complexity
Network
Attack vector
None
Availability
None
Confidentiality
High
Integrity
None
Privileges required
Unchanged
Scope
Required
User interaction
6.5
Base score
Exploitability score
Impact score
 

Verification logic

OR
AND
product=go-toolset-1.12-0 AND versionEndExcluding=1.12.12-4.el7
vendor=Red Hat Enterprise Linux AND product=devtools AND version=2019
AND
product=go-toolset-1.12-golang-0 AND versionEndExcluding=1.12.12-4.el7
vendor=Red Hat Enterprise Linux AND product=devtools AND version=2019
AND
product=go-toolset AND versionEndExcluding=rhel8-8010020191220185136.0ed30617
vendor=Red Hat Enterprise Linux AND product=enterprise_linux AND version=8
AND
product=openshift4/ose-baremetal-runtimecfg-rhel7 AND versionEndExcluding=v4.2.4-201911050122
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.2
AND
product=openshift4/ose-cli AND versionEndExcluding=v4.2.4-201911050122
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.2
AND
product=openshift4/ose-cli-artifacts AND versionEndExcluding=v4.2.4-201911050122
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.2
AND
product=openshift4/ose-cluster-authentication-operator AND versionEndExcluding=v4.2.4-201911050122
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.2
AND
product=openshift4/ose-cluster-dns-operator AND versionEndExcluding=v4.2.4-201911050122
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.2
AND
product=openshift4/ose-cluster-image-registry-operator AND versionEndExcluding=v4.2.4-201911050122
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.2
AND
product=openshift4/ose-cluster-ingress-operator AND versionEndExcluding=v4.2.4-201911050122
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.2
AND
product=openshift4/ose-cluster-kube-apiserver-operator AND versionEndExcluding=v4.2.4-201911050122
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.2
AND
product=openshift4/ose-cluster-kube-controller-manager-operator AND versionEndExcluding=v4.2.4-201911050122
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.2
AND
product=openshift4/ose-cluster-kube-scheduler-operator AND versionEndExcluding=v4.2.4-201911050122
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.2
AND
product=openshift4/ose-cluster-openshift-apiserver-operator AND versionEndExcluding=v4.2.4-201911050122
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.2
AND
product=openshift4/ose-cluster-openshift-controller-manager-operator AND versionEndExcluding=v4.2.4-201911050122
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.2
AND
product=openshift4/ose-cluster-svcat-apiserver-operator AND versionEndExcluding=v4.2.4-201911050122
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.2
AND
product=openshift4/ose-cluster-svcat-controller-manager-operator AND versionEndExcluding=v4.2.4-201911050122
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.2
AND
product=openshift4/ose-console-operator AND versionEndExcluding=v4.2.4-201911050122
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.2
AND
product=openshift4/ose-coredns AND versionEndExcluding=v4.2.4-201911050122
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.2
AND
product=openshift4/ose-gcp-machine-controllers-rhel7 AND versionEndExcluding=v4.2.4-201911050122
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.2
AND
product=openshift4/ose-hyperkube AND versionEndExcluding=v4.2.4-201911071146
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.2
AND
product=openshift4/ose-insights-rhel7-operator AND versionEndExcluding=v4.2.4-201911050122
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.2
AND
product=openshift4/ose-kube-proxy AND versionEndExcluding=v4.2.4-201911050122
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.2
AND
product=openshift4/ose-mdns-publisher-rhel7 AND versionEndExcluding=v4.2.4-201911050122
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.2
AND
product=openshift4/ose-node AND versionEndExcluding=v4.2.4-201911050122
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.2
AND
product=openshift4/ose-oauth-proxy AND versionEndExcluding=v4.2.4-201911050122
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.2
AND
product=openshift4/ose-openshift-apiserver-rhel7 AND versionEndExcluding=v4.2.4-201911050122
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.2
AND
product=openshift4/ose-openshift-controller-manager-rhel7 AND versionEndExcluding=v4.2.4-201911050122
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.2
AND
product=openshift4/ose-operator-lifecycle-manager AND versionEndExcluding=v4.2.4-201911050122
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.2
AND
product=openshift4/ose-operator-registry AND versionEndExcluding=v4.2.4-201911050122
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.2
AND
product=openshift4/ose-prometheus-alertmanager AND versionEndExcluding=v4.2.4-201911050122
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.2
AND
product=openshift4/ose-prometheus-node-exporter AND versionEndExcluding=v4.2.4-201911050122
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.2
AND
product=openshift4/ose-prometheus-operator AND versionEndExcluding=v4.2.4-201911050122
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.2
AND
product=openshift4/ose-sdn-controller-rhel7 AND versionEndExcluding=v4.2.4-201911050122
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.2
AND
product=openshift4/ose-service-ca-operator AND versionEndExcluding=v4.2.4-201911050122
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.2
AND
product=openshift4/ose-tests AND versionEndExcluding=v4.2.4-201911072324
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.2
AND
product=atomic-enterprise-service-catalog-1 AND versionEndExcluding=4.2.4-201911041319.git.1.1de4bcd.el7
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.2
AND
product=atomic-openshift-service-idler-0 AND versionEndExcluding=4.2.4-201911041319.git.1.4131c2f.el7
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.2
AND
product=openshift-0 AND versionEndExcluding=4.2.4-201911041319.git.0.c7d2111.el8
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.2
AND
product=openshift-clients-0 AND versionEndExcluding=4.2.4-201911010432.git.1.30c33a5.el8
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.2
AND
product=openshift-enterprise-autoheal-0 AND versionEndExcluding=4.2.4-201911010432.git.1.0b5cd44.el7
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.2
AND
product=openshift4/ose-installer AND versionEndExcluding=v4.2.21-202002240343
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.2
AND
product=openshift4/ose-installer-artifacts AND versionEndExcluding=v4.2.21-202002240343
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.2
AND
product=openshift4/ose-aws-machine-controllers AND versionEndExcluding=v4.3.0-202001211731
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.3
AND
product=openshift4/ose-azure-machine-controllers AND versionEndExcluding=v4.3.0-202001211731
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.3
AND
product=openshift4/ose-baremetal-machine-controllers AND versionEndExcluding=v4.3.0-202001211731
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.3
AND
product=openshift4/ose-cloud-credential-operator AND versionEndExcluding=v4.3.0-202001211731
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.3
AND
product=openshift4/ose-cluster-autoscaler AND versionEndExcluding=v4.3.0-202001211731
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.3
AND
product=openshift4/ose-cluster-autoscaler-operator AND versionEndExcluding=v4.3.0-202001211731
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.3
AND
product=openshift4/ose-cluster-bootstrap AND versionEndExcluding=v4.3.0-202001211731
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.3
AND
product=openshift4/ose-cluster-config-operator AND versionEndExcluding=v4.3.0-202001211731
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.3
AND
product=openshift4/ose-cluster-machine-approver AND versionEndExcluding=v4.3.0-202001211731
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.3
AND
product=openshift4/ose-cluster-monitoring-operator AND versionEndExcluding=v4.3.0-202001211731
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.3
AND
product=openshift4/ose-cluster-network-operator AND versionEndExcluding=v4.3.0-202001211731
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.3
AND
product=openshift4/ose-cluster-node-tuning-operator AND versionEndExcluding=v4.3.0-202001211731
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.3
AND
product=openshift4/ose-cluster-samples-operator AND versionEndExcluding=v4.3.0-202001211731
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.3
AND
product=openshift4/ose-cluster-storage-operator AND versionEndExcluding=v4.3.0-202001211731
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.3
AND
product=openshift4/ose-configmap-reloader AND versionEndExcluding=v4.3.0-202001211731
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.3
AND
product=openshift4/ose-console AND versionEndExcluding=v4.3.0-202001211731
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.3
AND
product=openshift4/ose-docker-builder AND versionEndExcluding=v4.3.0-202001211731
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.3
AND
product=openshift4/ose-docker-registry AND versionEndExcluding=v4.3.0-202001211731
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.3
AND
product=openshift4/ose-etcd AND versionEndExcluding=v4.3.0-202001211731
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.3
AND
product=openshift4/ose-grafana AND versionEndExcluding=v4.3.0-202001211731
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.3
AND
product=openshift4/ose-k8s-prometheus-adapter AND versionEndExcluding=v4.3.0-202001211731
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.3
AND
product=openshift4/ose-kube-rbac-proxy AND versionEndExcluding=v4.3.0-202001211731
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.3
AND
product=openshift4/ose-kube-state-metrics AND versionEndExcluding=v4.3.0-202001211731
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.3
AND
product=openshift4/ose-kuryr-cni-rhel8 AND versionEndExcluding=v4.3.0-202001211731
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.3
AND
product=openshift4/ose-libvirt-machine-controllers AND versionEndExcluding=v4.3.0-202001211731
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.3
AND
product=openshift4/ose-local-storage-static-provisioner AND versionEndExcluding=v4.3.0-202001211731
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.3
AND
product=openshift4/ose-machine-api-operator AND versionEndExcluding=v4.3.0-202001211731
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.3
AND
product=openshift4/ose-machine-config-operator AND versionEndExcluding=v4.3.0-202001211731
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.3
AND
product=openshift4/ose-multus-admission-controller AND versionEndExcluding=v4.3.0-202001211731
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.3
AND
product=openshift4/ose-multus-cni AND versionEndExcluding=v4.3.0-202001211731
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.3
AND
product=openshift4/ose-must-gather AND versionEndExcluding=v4.3.0-202001211731
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.3
AND
product=openshift4/ose-openstack-machine-controllers AND versionEndExcluding=v4.3.0-202001211731
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.3
AND
product=openshift4/ose-operator-marketplace AND versionEndExcluding=v4.3.0-202001211731
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.3
AND
product=openshift4/ose-ovn-kubernetes AND versionEndExcluding=v4.3.0-202001211731
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.3
AND
product=openshift4/ose-pod AND versionEndExcluding=v4.3.0-202001211731
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.3
AND
product=openshift4/ose-prometheus-config-reloader AND versionEndExcluding=v4.3.0-202001211731
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.3
AND
product=openshift4/ose-prom-label-proxy AND versionEndExcluding=v4.3.0-202001211731
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.3
AND
product=openshift4/ose-telemeter AND versionEndExcluding=v4.3.0-202001211731
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4.3
AND
product=golang AND version=
vendor=Red Hat Enterprise Linux AND product=ceph_storage AND version=2
AND
product=golang AND version=
vendor=Red Hat Enterprise Linux AND product=ceph_storage AND version=3
AND
product=gcc AND version=
vendor=Red Hat Enterprise Linux AND product=enterprise_linux AND version=7
AND
product=golang AND version=
vendor=Red Hat Enterprise Linux AND product=enterprise_linux AND version=7
AND
product=atomic-openshift AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=3.10
AND
product=ansible-service-broker AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=3.11
AND
product=apb AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=3.11
AND
product=atomic-enterprise-service-catalog AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=3.11
AND
product=atomic-openshift AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=3.11
AND
product=atomic-openshift-cluster-autoscaler AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=3.11
AND
product=atomic-openshift-descheduler AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=3.11
AND
product=atomic-openshift-dockerregistry AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=3.11
AND
product=atomic-openshift-metrics-server AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=3.11
AND
product=atomic-openshift-node-problem-detector AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=3.11
AND
product=atomic-openshift-service-idler AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=3.11
AND
product=atomic-openshift-web-console AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=3.11
AND
product=containernetworking-plugins AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=3.11
AND
product=cri-o AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=3.11
AND
product=cri-tools AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=3.11
AND
product=csi-attacher AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=3.11
AND
product=csi-driver-registrar AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=3.11
AND
product=csi-livenessprobe AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=3.11
AND
product=csi-provisioner AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=3.11
AND
product=golang-github-openshift-oauth-proxy AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=3.11
AND
product=golang-github-openshift-prometheus-alert-buffer AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=3.11
AND
product=golang-github-prometheus-alertmanager AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=3.11
AND
product=golang-github-prometheus-node_exporter AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=3.11
AND
product=golang-github-prometheus-prometheus AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=3.11
AND
product=golang-github-prometheus-promu AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=3.11
AND
product=hawkular-openshift-agent AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=3.11
AND
product=heapster AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=3.11
AND
product=image-inspector AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=3.11
AND
product=openshift-enterprise-autoheal AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=3.11
AND
product=openshift-enterprise-cluster-capacity AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=3.11
AND
product=openshift-enterprise-image-registry AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=3.11
AND
product=openshift-eventrouter AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=3.11
AND
product=openshift-external-storage AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=3.11
AND
product=openshift-monitor-project-lifecycle AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=3.11
AND
product=openshift-monitor-sample-app AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=3.11
AND
product=openvswitch-ovn-kubernetes AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=3.11
AND
product=podman AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=3.11
AND
product=atomic-openshift AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=3.9
AND
product=ansible-operator AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4
AND
product=ansible-service-broker AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4
AND
product=apb AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4
AND
product=containernetworking-plugins AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4
AND
product=cri-o AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4
AND
product=cri-tools AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4
AND
product=golang-github-openshift-prometheus-alert-buffer AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4
AND
product=golang-github-prometheus-promu AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4
AND
product=ignition AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4
AND
product=machine-config-daemon AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4
AND
product=openshift-eventrouter AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4
AND
product=openshift-external-storage AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4
AND
product=ose-installer-artifacts AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4
AND
product=podman AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4
AND
product=skopeo AND version=
vendor=Red Hat Enterprise Linux AND product=openshift AND version=4
AND
product=golang AND version=
vendor=Red Hat Enterprise Linux AND product=storage AND version=3
 

Reference

 


Keywords

REDHAT

 

CVE-2019-16276

 

CVE

 

Common vulnerabilities & exposures

 

CVSS

 

Common vulnerability scoring system

 

Security

 

Vulnerabilities

 

Exposures

 

We use cookies to ensure that we give you the best experience on our website. Read privacy policies for more information.