QID 996444

Date Published: 2023-12-26

QID 996444: Java (Maven) Security Update for golang.org/x/net (GHSA-qppj-fm5r-hxr3)

The HTTP/2 protocol allows clients to indicate to the server that a previous stream should be canceled by sending a RST_STREAM frame. The protocol does not require the client and server to coordinate the cancellation in any way, the client may do it unilaterally. The client may also assume that the cancellation will take effect immediately when the server receives the RST_STREAM frame, before any other data from that TCP connection is processed.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-qppj-fm5r-hxr3 for updates and patch information.
    Vendor References

    CVEs related to QID 996444

    Software Advisories
    Advisory ID Software Component Link
    GHSA-qppj-fm5r-hxr3 golang.org/x/net URL Logo github.com/advisories/GHSA-qppj-fm5r-hxr3