CVE-2022-27664 (High) detected in github.com/golang/net-290c469a71a567d354e4abd335577aba44c4bde4 #557
Labels
Mend: dependency security vulnerability
Security vulnerability detected by WhiteSource
CVE-2022-27664 - High Severity Vulnerability
Vulnerable Library - github.com/golang/net-290c469a71a567d354e4abd335577aba44c4bde4
[mirror] Go supplementary network libraries
Dependency Hierarchy:
Found in HEAD commit: 17dd063aa08781fc976ae77c2d99df67e5f02184
Found in base branch: main
Vulnerability Details
In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers can cause a denial of service because an HTTP/2 connection can hang during closing if shutdown were preempted by a fatal error.
Publish Date: 2022-09-06
URL: CVE-2022-27664
CVSS 3 Score Details (7.5)
Base Score Metrics:
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: