Vulnerability Description
Go before 1.14.8 and 1.15.x before 1.15.1 allows XSS because text/html is the default for CGI/FCGI handlers that lack a Content-Type header.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Golang | Go | < 1.14.8 |
| Fedoraproject | Fedora | 33 |
| Opensuse | Leap | 15.1 |
| Oracle | Communications Cloud Native Core Policy | 1.5.0 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00000.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00002.htmlMailing ListThird Party Advisory
- http://packetstormsecurity.com/files/159049/Go-CGI-FastCGI-Transport-Cross-Site-ExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2020/Sep/5ExploitMailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2020/Sep/5ExploitMailing ListThird Party Advisory
- https://groups.google.com/forum/#%21topic/golang-announce/8wqlSbkLdPs
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://security.netapp.com/advisory/ntap-20200924-0003/Third Party Advisory
- https://www.oracle.com//security-alerts/cpujul2021.htmlPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.htmlPatchThird Party Advisory
- https://www.redteam-pentesting.de/advisories/rt-sa-2020-004ExploitThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00000.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00002.htmlMailing ListThird Party Advisory
- http://packetstormsecurity.com/files/159049/Go-CGI-FastCGI-Transport-Cross-Site-ExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2020/Sep/5ExploitMailing ListThird Party Advisory
FAQ
What is CVE-2020-24553?
CVE-2020-24553 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Go before 1.14.8 and 1.15.x before 1.15.1 allows XSS because text/html is the default for CGI/FCGI handlers that lack a Content-Type header.
How severe is CVE-2020-24553?
CVE-2020-24553 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-24553?
Check the references section above for vendor advisories and patch information. Affected products include: Golang Go, Fedoraproject Fedora, Opensuse Leap, Oracle Communications Cloud Native Core Policy.