CVE Vulnerabilities

CVE-2022-26945

Published: May 25, 2022 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
9.8 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

go-getter up to 1.5.11 and 2.0.2 allowed protocol switching, endless redirect, and configuration bypass via abuse of custom HTTP response header processing. Fixed in 1.6.1 and 2.1.0.

Affected Software

NameVendorStart VersionEnd Version
Go-getterHashicorp*1.5.11 (including)
Go-getterHashicorp2.0.2 (including)2.0.2 (including)
Red Hat OpenShift Container Platform 4.10RedHatopenshift4/ose-baremetal-rhel8-operator:v4.10.0-202208182025.p0.g97ce15e.assembly.stream*
Red Hat OpenShift Container Platform 4.10RedHatopenshift4/ose-cluster-baremetal-operator-rhel8:v4.10.0-202208260945.p0.g23614bb.assembly.stream*
Red Hat OpenShift Container Platform 4.10RedHatopenshift4/ose-baremetal-machine-controllers:v4.10.0-202209301647.p0.gadff401.assembly.stream*
Red Hat OpenShift Container Platform 4.10RedHatopenshift4/ose-installer:v4.10.0-202210250219.p0.g1ffe666.assembly.stream*
Red Hat OpenShift Container Platform 4.11RedHatopenshift4/ose-baremetal-machine-controllers:v4.11.0-202208020235.p0.ga65be86.assembly.stream*
Red Hat OpenShift Container Platform 4.11RedHatopenshift4/ose-baremetal-rhel8-operator:v4.11.0-202208020235.p0.g22b522c.assembly.stream*
Red Hat OpenShift Container Platform 4.11RedHatopenshift4/ose-cluster-baremetal-operator-rhel8:v4.11.0-202208020235.p0.g0f415d1.assembly.stream*
Red Hat OpenShift Container Platform 4.11RedHatopenshift4/ose-installer:v4.11.0-202210250857.p0.g9d1e216.assembly.stream*
Red Hat OpenShift Container Platform 4.8RedHatopenshift4/ose-baremetal-rhel8-operator:v4.8.0-202208241844.p0.g5492cf5.assembly.stream*
Red Hat OpenShift Container Platform 4.8RedHatopenshift4/ose-cluster-baremetal-operator-rhel8:v4.8.0-202209291426.p0.g117d47a.assembly.stream*
Red Hat OpenShift Container Platform 4.8RedHatopenshift4/ose-baremetal-machine-controllers:v4.8.0-202211031007.p0.g2dabef7.assembly.stream*
Red Hat OpenShift Container Platform 4.9RedHatopenshift4/ose-baremetal-rhel8-operator:v4.9.0-202208231335.p0.g4e7605b.assembly.stream*
Red Hat OpenShift Container Platform 4.9RedHatopenshift4/ose-cluster-baremetal-operator-rhel8:v4.9.0-202210061647.p0.g1a49892.assembly.stream*
Red Hat OpenShift Container Platform 4.9RedHatopenshift4/ose-baremetal-machine-controllers:v4.9.0-202210241459.p0.g41aa1f7.assembly.stream*
Red Hat OpenShift Container Platform 4.9RedHatopenshift4/ose-installer:v4.9.0-202212060115.p0.gf079984.assembly.stream*
Red Hat OpenStack Platform 16.2RedHatrhosp-rhel8-tech-preview/osp-director-downloader:1.2.3-3*
Red Hat OpenStack Platform 16.2RedHatrhosp-rhel8-tech-preview/osp-director-operator:1.2.3-3*
Golang-github-hashicorp-go-getterUbuntubionic*
Golang-github-hashicorp-go-getterUbuntuesm-apps/bionic*
Golang-github-hashicorp-go-getterUbuntuesm-apps/focal*
Golang-github-hashicorp-go-getterUbuntuesm-apps/jammy*
Golang-github-hashicorp-go-getterUbuntuesm-apps/noble*
Golang-github-hashicorp-go-getterUbuntufocal*
Golang-github-hashicorp-go-getterUbuntuimpish*
Golang-github-hashicorp-go-getterUbuntujammy*
Golang-github-hashicorp-go-getterUbuntukinetic*
Golang-github-hashicorp-go-getterUbuntulunar*
Golang-github-hashicorp-go-getterUbuntumantic*
Golang-github-hashicorp-go-getterUbuntunoble*
Golang-github-hashicorp-go-getterUbuntuoracular*
Golang-github-hashicorp-go-getterUbuntuplucky*
Golang-github-hashicorp-go-getterUbuntuquesting*
Golang-github-hashicorp-go-getterUbuntuupstream*
Golang-github-jesseduffield-go-getterUbuntuesm-apps/focal*
Golang-github-jesseduffield-go-getterUbuntuesm-apps/jammy*
Golang-github-jesseduffield-go-getterUbuntuesm-apps/noble*
Golang-github-jesseduffield-go-getterUbuntufocal*
Golang-github-jesseduffield-go-getterUbuntujammy*
Golang-github-jesseduffield-go-getterUbuntumantic*
Golang-github-jesseduffield-go-getterUbuntunoble*
Golang-github-jesseduffield-go-getterUbuntuoracular*

References