445
VMScore

CVE-2021-23409

Published: 21/07/2021 Updated: 29/07/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The package github.com/pires/go-proxyproto prior to 0.6.0 are vulnerable to Denial of Service (DoS) via creating connections without the proxy protocol header.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

go-proxyproto project go-proxyproto

Vendor Advisories

Debian Bug report logs - #991498 golang-github-pires-go-proxyproto: CVE-2021-23409 Package: src:golang-github-pires-go-proxyproto; Maintainer for src:golang-github-pires-go-proxyproto is Debian Go Packaging Team <team+pkg-go@trackerdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Sun, 25 Jul 2021 1 ...