{"id":"GHSA-x477-fq37-q5wr","aliases":["GO-2023-1524"],"url":"https://o3.security/vulnerability/GHSA-x477-fq37-q5wr","summary":"Initial debug-host handler implementation could leak information and facilitate denial of service","details":"### Impact\nversion 1.5.0 and 1.6.0 when using the new `debug-host` feature could expose unnecessary information about the host\n\n### Patches\nUse 1.6.1 or newer\n\n### Workarounds\nDowngrade to 1.4.0 or set `debug-host` to empty\n\n### References\nhttps://github.com/fortio/proxy/pull/38\n\nQ&A https://github.com/fortio/proxy/discussions","published":"2023-01-27T00:55:27Z","modified":"2024-08-20T20:59:07.170624Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"fortio.org/proxy","fixedVersion":"1.6.1"}],"fix":{"url":"https://github.com/fortio/proxy/pull/38","label":"fortio/proxy#38"},"references":[{"type":"WEB","url":"https://github.com/fortio/proxy/security/advisories/GHSA-x477-fq37-q5wr"},{"type":"WEB","url":"https://github.com/fortio/proxy/pull/38"},{"type":"PACKAGE","url":"https://github.com/fortio/proxy"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-08-20T20:59:07.170624Z"}}