SB2019081442 - Input validation error in go (Alpine package)
Published: August 14, 2019
Security Bulletin ID
SB2019081442
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Data manipulation
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2019-14809)
The vulnerability allows a remote attacker to bypass certain security restrictions.
The vulnerability exists due to incorrect processing of URLs in net/url, related to the Host field with a suffix appearing in neither Hostname() nor Port(), and is related to a non-numeric port number. A remote attacker can create a crafted javascript:// URL that in certain situations can be used to bypass authorization checks for some applications.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=573b7537c7e1ab2732007a1d026a913613ca2d03
- https://git.alpinelinux.org/aports/commit/?id=17caf1ca31bcf51f92d7f466d287824869ec3f25
- https://git.alpinelinux.org/aports/commit/?id=27f348ba847da969ec1809cfd6d4f76455fc5405
- https://git.alpinelinux.org/aports/commit/?id=f4894bf9bd05edccdac484db35c4d6fb06a3b26c