CVE-2021-33195
Last modified
CVE-2021-33195 is a high-severity vulnerability rated 7.3/10 on the CVSS scale. Go before 1.15.13 and 1.16.x before 1.16.5 has functions for DNS lookups that do not validate replies from DNS servers, and thus a return value may contain an unsafe injection (e.g., XSS) that does not conform to the RFC1035 format.. EPSS estimates a 3.20% chance of exploitation in the next 30 days.
Description
Go before 1.15.13 and 1.16.x before 1.16.5 has functions for DNS lookups that do not validate replies from DNS servers, and thus a return value may contain an unsafe injection (e.g., XSS) that does not conform to the RFC1035 format.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Golang | Go | < 1.15.13 |
| Golang | Go | >= 1.16.0, < 1.16.5 |
| Netapp | Cloud Insights Telegraf Agent | All versions |
References
- https://groups.google.com/g/golang-announceThird Party Advisory
- https://groups.google.com/g/golang-announce/c/RgCMkAEQjSIExploit, Patch, Third Party Advisory
- https://security.gentoo.org/glsa/202208-02Third Party Advisory
- https://security.netapp.com/advisory/ntap-20210902-0005/Third Party Advisory
- https://groups.google.com/g/golang-announceThird Party Advisory
- https://groups.google.com/g/golang-announce/c/RgCMkAEQjSIExploit, Patch, Third Party Advisory
- https://security.gentoo.org/glsa/202208-02Third Party Advisory
- https://security.netapp.com/advisory/ntap-20210902-0005/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-33195?
How severe is CVE-2021-33195?
How do I fix CVE-2021-33195?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-3319DOS: Incorrect 802154 Frame Validation for Omitted Source / …9.8
- CVE-2021-33190In Apache APISIX Dashboard version 2.6, we changed the defau…5.3
- CVE-2021-33191From Apache NiFi MiNiFi C++ version 0.5.0 the c2 protocol im…9.8
- CVE-2021-33192A vulnerability in the HTML pages of Apache Jena Fuseki allo…6.1
- CVE-2021-33193A crafted method sent through HTTP/2 will bypass validation …7.5
- CVE-2021-33194golang.org/x/net before v0.0.0-20210520170846-37e1c6afe023 a…7.5
- CVE-2021-33196In archive/zip in Go before 1.15.13 and 1.16.x before 1.16.5…7.5
- CVE-2021-33197In Go before 1.15.13 and 1.16.x before 1.16.5, some configur…5.3
- CVE-2021-33198In Go before 1.15.13 and 1.16.x before 1.16.5, there can be …7.5
- CVE-2021-33199In Expression Engine before 6.0.3, addonIcon in Addons/file/…9.8
- CVE-2021-3320Type Confusion in 802154 ACK Frames Handling. Zephyr version…7.5
- CVE-2021-33200kernel/bpf/verifier.c in the Linux kernel through 5.12.7 enf…7.8
Are you affected by CVE-2021-33195?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
