CVE-2021-33195
Go before 1.15.13 and 1.16.x before 1.16.5 has functions for DNS lookups that do not validate replies from DNS servers, and thus a return value may contain an unsafe injection (e.g., XSS) that does not conform to the RFC1035 format.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.23%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Go before 1.15.13 and 1.16.x before 1.16.5 has functions for DNS lookups that do not validate replies from DNS servers, and thus a return value may contain an unsafe injection (e.g., XSS) that does not conform to the RFC1035 format.
- CVSS 3.1
- 7.3 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- EPSS
- 3.23% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-74
- Affected
- golang/go · netapp/cloud insights telegraf agent
- Source
- cve@mitre.org
References
- https://groups.google.com/g/golang-announceThird Party Advisory
- https://groups.google.com/g/golang-announce/c/RgCMkAEQjSIExploit, Patch, Third Party Advisory
- https://security.gentoo.org/glsa/202208-02Third Party Advisory
- https://security.netapp.com/advisory/ntap-20210902-0005/Third Party Advisory
- https://groups.google.com/g/golang-announceThird Party Advisory
- https://groups.google.com/g/golang-announce/c/RgCMkAEQjSIExploit, Patch, Third Party Advisory
- https://security.gentoo.org/glsa/202208-02Third Party Advisory
- https://security.netapp.com/advisory/ntap-20210902-0005/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.