QID 996444
Date Published: 2023-12-26
QID 996444: Java (Maven) Security Update for golang.org/x/net (GHSA-qppj-fm5r-hxr3)
The HTTP/2 protocol allows clients to indicate to the server that a previous stream should be canceled by sending a RST_STREAM frame. The protocol does not require the client and server to coordinate the cancellation in any way, the client may do it unilaterally. The client may also assume that the cancellation will take effect immediately when the server receives the RST_STREAM frame, before any other data from that TCP connection is processed.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-qppj-fm5r-hxr3 for updates and patch information.
Vendor References
- GHSA-qppj-fm5r-hxr3 -
github.com/advisories/GHSA-qppj-fm5r-hxr3
CVEs related to QID 996444
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-qppj-fm5r-hxr3 | golang.org/x/net |
|