Vulnerability Description
The package github.com/pires/go-proxyproto before 0.6.0 are vulnerable to Denial of Service (DoS) via creating connections without the proxy protocol header.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Go-Proxyproto Project | Go-Proxyproto | < 0.6.0 |
References
- https://github.com/pires/go-proxyproto/issues/65Issue TrackingThird Party Advisory
- https://github.com/pires/go-proxyproto/pull/74PatchThird Party Advisory
- https://github.com/pires/go-proxyproto/pull/74/commits/cdc63867da24fc609b727231fPatchThird Party Advisory
- https://github.com/pires/go-proxyproto/releases/tag/v0.6.0Release NotesThird Party Advisory
- https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMPIRESGOPROXYPROTO-1316439PatchThird Party Advisory
- https://github.com/pires/go-proxyproto/issues/65Issue TrackingThird Party Advisory
- https://github.com/pires/go-proxyproto/pull/74PatchThird Party Advisory
- https://github.com/pires/go-proxyproto/pull/74/commits/cdc63867da24fc609b727231fPatchThird Party Advisory
- https://github.com/pires/go-proxyproto/releases/tag/v0.6.0Release NotesThird Party Advisory
- https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMPIRESGOPROXYPROTO-1316439PatchThird Party Advisory
FAQ
What is CVE-2021-23409?
CVE-2021-23409 is a vulnerability with a CVSS score of 7.5 (HIGH). The package github.com/pires/go-proxyproto before 0.6.0 are vulnerable to Denial of Service (DoS) via creating connections without the proxy protocol header.
How severe is CVE-2021-23409?
CVE-2021-23409 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-23409?
Check the references section above for vendor advisories and patch information. Affected products include: Go-Proxyproto Project Go-Proxyproto.