Bug 2224245 (CVE-2023-37788)

Summary: CVE-2023-37788 goproxy: Denial of service (DoS) via unspecified vectors.
Product: [Other] Security Response Reporter: Vipul Nair <vinair>
Component: vulnerabilityAssignee: Nobody <nobody>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: aazores, amasferr, amctagga, bdettelb, chazlett, dfreiber, dhughes, dsimansk, dymurray, eaguilar, ebaron, eglynn, ellin, gparvin, ibolton, jburrell, jcantril, jjoyce, jkang, jkoehler, jkurik, jmatthew, jmontleo, joelsmith, jpallich, jschluet, lball, lgamliel, lhh, matzew, mburns, mgarciac, mkudlej, muagarwa, mwringe, nathans, nbecker, njean, nobody, owatkins, pahickey, pcpbot, pgrist, pjindal, rfreiman, rhos-maint, rhuss, rogbas, scorneli, sfroberg, shbose, slucidi, sseago, stcannon, teagle, tjochec, tnielsen, vkumar
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in goproxy, which is vulnerable to a denial of service caused by improper input validation. This flaw allows a remote attacker can cause the goproxy server to crash by sending a specially crafted HTTP request to the HTTPS page, replacing the path "/" with an asterisk "*".
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2224298, 2224299, 2224300, 2224301, 2224302, 2224303, 2224304, 2224305, 2224306, 2224307, 2224308, 2224314, 2224315, 2224316, 2224322, 2225359    
Bug Blocks: 2220974    

Description Vipul Nair 2023-07-20 09:05:23 UTC
goproxy v1.1 was discovered to contain an issue which can lead to a Denial of service (DoS) via unspecified vectors.

https://github.com/elazarl/goproxy/issues/502
https://github.com/elazarl/goproxy

Comment 16 Avinash Hanwate 2023-07-25 04:43:22 UTC
Created origin tracking bugs for this issue:

Affects: fedora-all [bug 2225359]

Comment 19 errata-xmlrpc 2023-09-29 14:13:21 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift GitOps 1.10

Via RHSA-2023:5407 https://access.redhat.com/errata/RHSA-2023:5407

Comment 20 Jon Schlueter 2023-10-18 16:14:29 UTC
From reading Issue in upstream repo it is fixed in attached pull request

Comment 22 errata-xmlrpc 2023-10-31 12:54:54 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.14

Via RHSA-2023:5006 https://access.redhat.com/errata/RHSA-2023:5006

Comment 23 errata-xmlrpc 2023-10-31 13:45:27 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.14

Via RHSA-2023:5007 https://access.redhat.com/errata/RHSA-2023:5007

Comment 24 errata-xmlrpc 2023-10-31 14:02:07 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.14

Via RHSA-2023:5009 https://access.redhat.com/errata/RHSA-2023:5009

Comment 25 errata-xmlrpc 2023-11-08 18:49:39 UTC
This issue has been addressed in the following products:

  RHODF-4.14-RHEL-9

Via RHSA-2023:6832 https://access.redhat.com/errata/RHSA-2023:6832

Comment 31 errata-xmlrpc 2024-02-27 20:49:27 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.15

Via RHSA-2023:7198 https://access.redhat.com/errata/RHSA-2023:7198

Comment 37 errata-xmlrpc 2024-05-15 18:43:52 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.15

Via RHSA-2024:2773 https://access.redhat.com/errata/RHSA-2024:2773

Comment 38 errata-xmlrpc 2024-05-29 21:40:13 UTC
This issue has been addressed in the following products:

  Red Hat OpenStack Platform 16.2

Via RHSA-2024:3479 https://access.redhat.com/errata/RHSA-2024:3479

Comment 41 errata-xmlrpc 2024-08-07 10:18:57 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.14

Via RHSA-2024:4959 https://access.redhat.com/errata/RHSA-2024:4959

Comment 42 errata-xmlrpc 2024-10-03 11:01:21 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.14

Via RHSA-2024:7184 https://access.redhat.com/errata/RHSA-2024:7184