Vulnerability Name:

CVE-2019-16276 (CCN-167963)

Assigned:2019-09-25
Published:2019-09-25
Updated:2021-03-22
Summary:Go before 1.12.10 and 1.13.x before 1.13.1 allow HTTP Request Smuggling.
CVSS v3 Severity:7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): High
Availibility (A): None
5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
6.5 Medium (REDHAT CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N)
5.7 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): High
Availibility (A): None
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-444
Vulnerability Consequences:Bypass Security
References:Source: MITRE
Type: CNA
CVE-2019-16276

Source: SUSE
Type: Mailing List, Third Party Advisory
openSUSE-SU-2019:2522

Source: SUSE
Type: Mailing List, Third Party Advisory
openSUSE-SU-2019:2521

Source: REDHAT
Type: Third Party Advisory
RHSA-2020:0101

Source: REDHAT
Type: Third Party Advisory
RHSA-2020:0329

Source: REDHAT
Type: Third Party Advisory
RHSA-2020:0652

Source: XF
Type: UNKNOWN
golang-cve201916276-sec-bypass(167963)

Source: CONFIRM
Type: Patch, Third Party Advisory
https://github.com/golang/go/issues/34540

Source: CCN
Type: Golang Web site
Go

Source: MISC
Type: Mailing List, Third Party Advisory
https://groups.google.com/forum/#!msg/golang-announce/cszieYyuL9Q/g4Z7pKaqAgAJ

Source: MLIST
Type: Mailing List, Third Party Advisory
[debian-lts-announce] 20210313 [SECURITY] [DLA 2591-1] golang-1.7 security update

Source: MLIST
Type: Mailing List, Third Party Advisory
[debian-lts-announce] 20210313 [SECURITY] [DLA 2592-1] golang-1.8 security update

Source: FEDORA
Type: Third Party Advisory
FEDORA-2019-1b8cbd39ff

Source: FEDORA
Type: Third Party Advisory
FEDORA-2019-e99c1603c3

Source: FEDORA
Type: Third Party Advisory
FEDORA-2019-416d20f960

Source: CCN
Type: BugTraq Mailing List, Fri, 27 Sep 2019 20:36:57 +0000
[DSA 4534-1] golang-1.11 security update

Source: CONFIRM
Type: Third Party Advisory
https://security.netapp.com/advisory/ntap-20191122-0004/

Source: CCN
Type: IBM Security Bulletin 1164448 (Cloud Private)
A Security Vulnerability affects IBM Cloud Private - Go (CVE-2019-16276)

Source: CCN
Type: IBM Security Bulletin 6221690 (Spectrum Protect Server)
Vulnerability in Go programming language affects IBM Spectrum Protect Server (CVE-2019-16276)

Source: CCN
Type: IBM Security Bulletin 6226390 (Event Streams)
IBM Event Streams is affected by Go vulnerability CVE-2019-16276

Source: CCN
Type: IBM Security Bulletin 6323255 (ICP Discovery)
IBM Watson Discovery for IBM Cloud Pak for Data affected by vulnerability in Go

Source: CCN
Type: IBM Security Bulletin 6568787 (Cloud Pak for Security)
Cloud Pak for Security contains packages that have multiple vulnerabilities

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2019-16276

Vulnerable Configuration:Configuration 1:
  • cpe:/a:golang:go:*:*:*:*:*:*:*:* (Version < 1.12.10)
  • OR cpe:/a:golang:go:*:*:*:*:*:*:*:* (Version >= 1.13 and < 1.13.1)

  • Configuration 2:
  • cpe:/o:debian:debian_linux:9.0:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:opensuse:leap:15.0:*:*:*:*:*:*:*
  • OR cpe:/o:opensuse:leap:15.1:*:*:*:*:*:*:*

  • Configuration 4:
  • cpe:/o:fedoraproject:fedora:29:*:*:*:*:*:*:*
  • OR cpe:/o:fedoraproject:fedora:30:*:*:*:*:*:*:*
  • OR cpe:/o:fedoraproject:fedora:31:*:*:*:*:*:*:*

  • Configuration 5:
  • cpe:/a:redhat:openshift_container_platform:4.2:*:*:*:*:*:*:*
  • AND
  • cpe:/o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*

  • Configuration 6:
  • cpe:/a:redhat:developer_tools:1.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_eus:8.1:*:*:*:*:*:*:*

  • Configuration 7:
  • cpe:/a:netapp:cloud_insights_telegraf_agent:-:*:*:*:*:*:*:*

  • Configuration RedHat 1:
  • cpe:/a:redhat:enterprise_linux:8:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/a:redhat:enterprise_linux:8::appstream:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:golang:go:1.12.9:*:*:*:*:*:*:*
  • OR cpe:/a:golang:go:1.13:-:*:*:*:*:*:*
  • AND
  • cpe:/a:ibm:event_streams:2019.2.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:cloud_private:3.2.0:cd:*:*:*:*:*:*
  • OR cpe:/a:ibm:cloud_private:3.2.1:cd:*:*:*:*:*:*
  • OR cpe:/a:ibm:cloud_private:3.2.0:cd:*:*:*:*:*:*
  • OR cpe:/a:ibm:cloud_private:3.2.1:cd:*:*:*:*:*:*
  • OR cpe:/a:ibm:event_streams:2019.2.2:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:event_streams:2019.2.3:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:event_streams:2019.4.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:spectrum_protect_server:8.1.0.000:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:spectrum_protect_server:8.1.9.300:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:51965
    P
    Security update for libdb-4_8 (Low)
    2022-11-24
    oval:org.opensuse.security:def:201916276
    V
    CVE-2019-16276
    2022-09-02
    oval:org.opensuse.security:def:3313
    P
    ovmf-2017+git1510945757.b2662641d5-3.16.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3325
    P
    perl-Config-IniFiles-2.82-3.12 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3582
    P
    libcdio14-0.90-6.3.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3594
    P
    libgc1-7.2d-5.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:2875
    P
    bcm43xx-firmware-20180314-150400.28.5 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:2934
    P
    glib2-devel-2.70.4-150400.1.5 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:2857
    P
    Mesa-21.2.4-150400.66.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:2904
    P
    cyrus-sasl-saslauthd-2.1.27-150300.4.6.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:2889
    P
    clamav-0.103.5-3.35.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:2942
    P
    groff-1.22.4-150400.3.4 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:2944
    P
    gssproxy-0.8.2-3.9.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:2863
    P
    apparmor-abstractions-3.0.4-150400.3.4 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:2928
    P
    gdk-pixbuf-devel-2.42.6-150400.3.8 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:2895
    P
    cpp7-7.5.0+r278197-4.30.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:112332
    P
    go1.13-1.13.15-2.6 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:112331
    P
    go1.12-1.12.17-4.8 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:74330
    P
    Security update for ImageMagick (Moderate)
    2021-12-10
    oval:org.opensuse.security:def:51696
    P
    Security update for the Linux Kernel (Live Patch 40 for SLE 12 SP3) (Important)
    2021-11-19
    oval:org.opensuse.security:def:105853
    P
    Security update for salt (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:105852
    P
    go1.12-1.12.17-4.8 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:49452
    P
    Security update for nodejs14 (Important)
    2021-09-22
    oval:org.opensuse.security:def:63203
    P
    dpdk-18.11-2.43 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:63341
    P
    libmariadb-devel-3.1.12-3.25.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63001
    P
    ctags-5.8-1.27 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:72078
    P
    tboot-20170711_1.9.8-15.9.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:51758
    P
    Security update for wavpack (Important)
    2021-03-24
    oval:org.opensuse.security:def:49120
    P
    Security update for rubygem-archive-tar-minitar (Moderate)
    2021-01-13
    oval:org.opensuse.security:def:52027
    P
    Security update for MozillaFirefox (Important)
    2021-01-12
    oval:org.opensuse.security:def:64278
    P
    Security update for clamav (Moderate)
    2020-12-14
    oval:org.opensuse.security:def:72194
    P
    libtiff5-32bit-4.0.9-3.15 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62722
    P
    typelib-1_0-JavaScriptCore-4_0-2.28.2-1.11 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62521
    P
    gdm-3.26.2.1-13.19.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62545
    P
    libass-devel-0.14.0-1.25 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63567
    P
    argyllcms-1.9.2-2.27 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62522
    P
    gnome-online-accounts-devel-3.26.2-3.34 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2588
    P
    Security update for python-pip (Important)
    2020-12-02
    oval:org.opensuse.security:def:2853
    P
    Security update for jasper (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:2635
    P
    Security update for libopenmpt (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:2620
    P
    Security update for podman (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:2673
    P
    Security update for libnettle (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:2675
    P
    Security update for MozillaFirefox, mozilla-nspr and mozilla-nss (Important)
    2020-12-02
    oval:org.opensuse.security:def:2594
    P
    Security update for cf-cli (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:2659
    P
    Security update for wireshark (Important)
    2020-12-02
    oval:org.opensuse.security:def:68738
    P
    Security update for python-cryptography (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:2626
    P
    Security update for containerd, docker, docker-runc, golang-github-docker-libnetwork (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:2584
    P
    Security update for postgresql10 (Important)
    2020-12-02
    oval:org.opensuse.security:def:2606
    P
    Security update for containerd, docker, docker-runc, go, go1.11, go1.12, golang-github-docker-libnetwork (Important)
    2020-12-02
    oval:org.opensuse.security:def:2665
    P
    Security update for accountsservice (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:49247
    P
    libtspi1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64134
    P
    Security update for xerces-c (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50091
    P
    python3-pywbem on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49867
    P
    xorg-x11-server-sdk on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64390
    P
    libsystemd0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50520
    P
    Security update for samba (Important)
    2020-12-01
    oval:org.opensuse.security:def:49102
    P
    git-core on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:63894
    P
    Security update for apache2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:65404
    P
    Security update for openexr (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49696
    P
    libsrtp-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50689
    P
    Security update for python3 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49516
    P
    gdk-pixbuf-query-loaders-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50360
    P
    Security update for MozillaFirefox, mozilla-nspr and mozilla-nss (Important)
    2020-12-01
    oval:org.opensuse.security:def:49101
    P
    giflib-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64236
    P
    cyrus-sasl on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50181
    P
    dia on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:65494
    P
    Security update for xorg-x11-server (Important)
    2020-12-01
    oval:org.opensuse.security:def:49371
    P
    containerd on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49965
    P
    libwsman-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50347
    P
    Security update for postgresql10 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64028
    P
    Security update for mozilla-nspr, mozilla-nss (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49370
    P
    zypper on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49853
    P
    pam-devel-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49721
    P
    wavpack on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50316
    P
    Security update for libxml2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50450
    P
    Security update for qemu (Important)
    2020-12-01
    oval:org.opensuse.security:def:68841
    P
    Security update for go1.12 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:74456
    P
    Security update for go1.12 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49598
    P
    rtkit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50616
    P
    Security update for samba (Important)
    2020-12-01
    oval:org.opensuse.security:def:50251
    P
    openconnect on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49389
    P
    accountsservice on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50122
    P
    nodejs10 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50420
    P
    Security update for postgresql10 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50585
    P
    Security update for wicked (Important)
    2020-12-01
    oval:com.redhat.rhsa:def:20200329
    P
    RHSA-2020:0329: go-toolset:rhel8 security update (Moderate)
    2020-02-04
    oval:org.opensuse.security:def:110080
    P
    Security update for go1.12 (Moderate)
    2019-11-17
    oval:org.opensuse.security:def:104515
    P
    Security update for go1.12 (Moderate)
    2019-11-11
    oval:org.opensuse.security:def:90860
    P
    Security update for go1.12 (Moderate)
    2019-11-11
    oval:org.opensuse.security:def:97825
    P
    Security update for go1.12 (Moderate)
    2019-11-11
    oval:com.ubuntu.disco:def:2019162760000000
    V
    CVE-2019-16276 on Ubuntu 19.04 (disco) - medium.
    2019-09-30
    oval:com.ubuntu.bionic:def:2019162760000000
    V
    CVE-2019-16276 on Ubuntu 18.04 LTS (bionic) - medium.
    2019-09-30
    oval:com.ubuntu.xenial:def:2019162760000000
    V
    CVE-2019-16276 on Ubuntu 16.04 LTS (xenial) - medium.
    2019-09-30
    BACK
    golang go *
    golang go *
    debian debian linux 9.0
    opensuse leap 15.0
    opensuse leap 15.1
    fedoraproject fedora 29
    fedoraproject fedora 30
    fedoraproject fedora 31
    redhat openshift container platform 4.2
    redhat enterprise linux 7.0
    redhat developer tools 1.0
    redhat enterprise linux 8.0
    redhat enterprise linux eus 8.1
    netapp cloud insights telegraf agent -
    golang go 1.12.9
    golang go 1.13 -
    ibm event streams 2019.2.1
    ibm cloud private 3.2.0 cd
    ibm cloud private 3.2.1 cd
    ibm cloud private 3.2.0 cd
    ibm cloud private 3.2.1 cd
    ibm event streams 2019.2.2
    ibm event streams 2019.2.3
    ibm event streams 2019.4.1
    ibm spectrum protect server 8.1.0.000
    ibm spectrum protect server 8.1.9.300