CVE-2021-33195
Last modified
CVE-2021-33195 is a high-severity vulnerability rated 7.3/10 on the CVSS scale. Go before 1.15.13 and 1.16.x before 1.16.5 has functions for DNS lookups that do not validate replies from DNS servers, and thus a return value may contain an unsafe injection (e.g., XSS) that does not conform to the RFC1035 format.. EPSS estimates a 3.20% chance of exploitation in the next 30 days.
Description
Go before 1.15.13 and 1.16.x before 1.16.5 has functions for DNS lookups that do not validate replies from DNS servers, and thus a return value may contain an unsafe injection (e.g., XSS) that does not conform to the RFC1035 format.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Golang | Go | < 1.15.13 |
| Golang | Go | >= 1.16.0, < 1.16.5 |
| Netapp | Cloud Insights Telegraf Agent | All versions |
References
- https://groups.google.com/g/golang-announceThird Party Advisory
- https://groups.google.com/g/golang-announce/c/RgCMkAEQjSIExploit, Patch, Third Party Advisory
- https://security.gentoo.org/glsa/202208-02Third Party Advisory
- https://security.netapp.com/advisory/ntap-20210902-0005/Third Party Advisory
- https://groups.google.com/g/golang-announceThird Party Advisory
- https://groups.google.com/g/golang-announce/c/RgCMkAEQjSIExploit, Patch, Third Party Advisory
- https://security.gentoo.org/glsa/202208-02Third Party Advisory
- https://security.netapp.com/advisory/ntap-20210902-0005/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-33195?
How severe is CVE-2021-33195?
How do I fix CVE-2021-33195?
Are you affected by CVE-2021-33195?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
