CVE-2022-1705: Improper sanitization of Transfer-Encoding headers in net/http
A flaw was found in golang. The HTTP/1 client accepted invalid Transfer-Encoding headers indicating "chunked" encoding. This issue could allow request smuggling, but only if combined with an intermediate server that also improperly accepts the header as invalid.
Other sources
Acceptance of some invalid Transfer-Encoding headers in the HTTP/1 client in net/http before Go 1.17.12 and Go 1.18.4 allows HTTP request smuggling if combined with an intermediate server that also improperly fails to reject the header as invalid.
Improper sanitization of Transfer-Encoding headers in net/http
— Microsoft
The HTTP/1 client accepted some invalid Transfer-Encoding headers as indicating a "chunked" encoding. This could potentially allow for request smuggling, but only if combined with an intermediate server that also improperly failed to reject the header as invalid.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/skupper-clito a version that resolves this vulnerability.Fixed in 0:1.0.2-2.el8 - Upgrade
Upgrade
redhat/libsodiumto a version that resolves this vulnerability.Fixed in 0:1.0.16-5.el8 - Upgrade
Upgrade
redhat/openstack-ironicto a version that resolves this vulnerability.Fixed in 1:20.2.1-0.20220628175043.b5ed57a.el8 - Upgrade
Upgrade
redhat/openstack-ironic-inspectorto a version that resolves this vulnerability.Fixed in 0:10.12.1-0.20220513095437.6dd37e5.el8 - Upgrade
Upgrade
redhat/openstack-ironic-python-agentto a version that resolves this vulnerability.Fixed in 0:8.6.1-0.20220623075054.1d50c23.el8 - Upgrade
Upgrade
redhat/pyparsingto a version that resolves this vulnerability.Fixed in 0:2.3.1-2.el8 - Upgrade
Upgrade
redhat/pysnmpto a version that resolves this vulnerability.Fixed in 0:4.4.8-3.el8 - Upgrade
Upgrade
redhat/python-alembicto a version that resolves this vulnerability.Fixed in 0:1.4.2-6.el8 - Upgrade
Upgrade
redhat/python-amqpto a version that resolves this vulnerability.Fixed in 0:2.5.2-8.el8 - Upgrade
Upgrade
redhat/python-appdirsto a version that resolves this vulnerability.Fixed in 0:1.4.0-8.el8 - Upgrade
Upgrade
redhat/python-automatonto a version that resolves this vulnerability.Fixed in 0:2.5.0-0.20220509195848.aaca110.el8 - Upgrade
Upgrade
redhat/python-bcryptto a version that resolves this vulnerability.Fixed in 0:3.1.6-3.el8 - Upgrade
Upgrade
redhat/python-beautifulsoup4to a version that resolves this vulnerability.Fixed in 0:4.9.3-2.el8 - Upgrade
Upgrade
redhat/python-cachetoolsto a version that resolves this vulnerability.Fixed in 0:3.1.0-3.el8 - Upgrade
Upgrade
redhat/python-cinderclientto a version that resolves this vulnerability.Fixed in 0:8.3.0-0.20220509212734.ee59b68.el8 - Upgrade
Upgrade
redhat/python-cliffto a version that resolves this vulnerability.Fixed in 0:3.10.1-0.20220509200732.a04a48f.el8 - Upgrade
Upgrade
redhat/python-coloramato a version that resolves this vulnerability.Fixed in 0:0.4.1-2.el8 - Upgrade
Upgrade
redhat/python-constructto a version that resolves this vulnerability.Fixed in 0:2.10.56-2.el8 - Upgrade
Upgrade
redhat/python-dataclassesto a version that resolves this vulnerability.Fixed in 0:0.8-3.el8 - Upgrade
Upgrade
redhat/python-debtcollectorto a version that resolves this vulnerability.Fixed in 0:2.5.0-0.20220509211533.a6b46c5.el8 - Upgrade
Upgrade
redhat/python-decoratorto a version that resolves this vulnerability.Fixed in 0:4.4.0-6.el8 - Upgrade
Upgrade
redhat/python-dogpile-cacheto a version that resolves this vulnerability.Fixed in 0:1.1.2-2.el8 - Upgrade
Upgrade
redhat/python-dracclientto a version that resolves this vulnerability.Fixed in 0:8.0.0-0.20220509201613.9c7499c.el8 - Upgrade
Upgrade
redhat/python-editorto a version that resolves this vulnerability.Fixed in 0:1.0.4-5.el8 - Upgrade
Upgrade
redhat/python-fastenersto a version that resolves this vulnerability.Fixed in 0:0.14.1-21.el8 - Upgrade
Upgrade
redhat/python-flaskto a version that resolves this vulnerability.Fixed in 1:1.1.1-2.el8 - Upgrade
Upgrade
redhat/python-funcsigsto a version that resolves this vulnerability.Fixed in 0:1.0.2-17.el8 - Upgrade
Upgrade
redhat/python-futuristto a version that resolves this vulnerability.Fixed in 0:2.4.1-0.20220509215250.159d752.el8 - Upgrade
Upgrade
redhat/python-glanceclientto a version that resolves this vulnerability.Fixed in 1:3.6.0-0.20220509212414.626c500.el8 - Upgrade
Upgrade
redhat/python-greenletto a version that resolves this vulnerability.Fixed in 0:0.4.14-6.el8 - Upgrade
Upgrade
redhat/python-hardwareto a version that resolves this vulnerability.Fixed in 0:0.29.0-0.20220216015636.7662a1d.el8 - Upgrade
Upgrade
redhat/python-ifaddrto a version that resolves this vulnerability.Fixed in 0:0.1.6-6.el8 - Upgrade
Upgrade
redhat/python-importlib-metadatato a version that resolves this vulnerability.Fixed in 0:1.7.0-2.el8 - Upgrade
Upgrade
redhat/python-ironic-libto a version that resolves this vulnerability.Fixed in 0:5.1.1-0.20220225151335.e205816.el8 - Upgrade
Upgrade
redhat/python-ironic-prometheus-exporterto a version that resolves this vulnerability.Fixed in 0:3.1.1-0.20220324125409.db1a824.el8 - Upgrade
Upgrade
redhat/python-iso8601to a version that resolves this vulnerability.Fixed in 0:0.1.12-9.el8 - Upgrade
Upgrade
redhat/python-jsonpath-rwto a version that resolves this vulnerability.Fixed in 0:1.2.3-23.el8 - Upgrade
Upgrade
redhat/python-jsonschemato a version that resolves this vulnerability.Fixed in 0:3.2.0-6.el8 - Upgrade
Upgrade
redhat/python-kazooto a version that resolves this vulnerability.Fixed in 0:2.7.0-2.el8 - Upgrade
Upgrade
redhat/python-keyringto a version that resolves this vulnerability.Fixed in 0:21.0.0-2.el8 - Upgrade
Upgrade
redhat/python-keystoneauth1to a version that resolves this vulnerability.Fixed in 0:4.5.0-0.20220509213157.8da0a63.el8 - Upgrade
Upgrade
redhat/python-keystoneclientto a version that resolves this vulnerability.Fixed in 1:4.4.0-0.20220509200759.100253d.el8 - Upgrade
Upgrade
redhat/python-keystonemiddlewareto a version that resolves this vulnerability.Fixed in 0:9.4.0-0.20220509211054.8a05709.el8 - Upgrade
Upgrade
redhat/python-kombuto a version that resolves this vulnerability.Fixed in 1:4.6.6-8.el8 - Upgrade
Upgrade
redhat/python-logutilsto a version that resolves this vulnerability.Fixed in 0:0.3.5-7.1.el8 - Upgrade
Upgrade
redhat/python-memcachedto a version that resolves this vulnerability.Fixed in 0:1.58-12.el8 - Upgrade
Upgrade
redhat/python-migrateto a version that resolves this vulnerability.Fixed in 0:0.13.0-2.el8 - Upgrade
Upgrade
redhat/python-msgpackto a version that resolves this vulnerability.Fixed in 0:0.6.2-2.el8 - Upgrade
Upgrade
redhat/python-munchto a version that resolves this vulnerability.Fixed in 0:2.3.2-7.el8 - Upgrade
Upgrade
redhat/python-openstacksdkto a version that resolves this vulnerability.Fixed in 0:0.61.0-0.20220509201549.26c9bc2.el8 - Upgrade
Upgrade
redhat/python-osc-libto a version that resolves this vulnerability.Fixed in 0:2.5.0-0.20220509211843.78d276e.el8 - Upgrade
Upgrade
redhat/python-oslo-cacheto a version that resolves this vulnerability.Fixed in 0:2.8.1-0.20220216000746.40946a9.el8 - Upgrade
Upgrade
redhat/python-oslo-concurrencyto a version that resolves this vulnerability.Fixed in 0:4.5.1-0.20220509221157.145f060.el8 - Upgrade
Upgrade
redhat/python-oslo-configto a version that resolves this vulnerability.Fixed in 2:8.8.0-0.20220509202553.64c82a0.el8 - Upgrade
Upgrade
redhat/python-oslo-contextto a version that resolves this vulnerability.Fixed in 0:4.1.0-0.20220509205437.3400cc2.el8 - Upgrade
Upgrade
redhat/python-oslo-dbto a version that resolves this vulnerability.Fixed in 0:9.1.0-0.20220216003829.be2cc6a.el8 - Upgrade
Upgrade
redhat/python-oslo-i18nto a version that resolves this vulnerability.Fixed in 0:5.1.0-0.20220216011159.b031d17.el8 - Upgrade
Upgrade
redhat/python-oslo-logto a version that resolves this vulnerability.Fixed in 0:4.6.0-0.20220216002407.41c8807.el8 - Upgrade
Upgrade
redhat/python-oslo-messagingto a version that resolves this vulnerability.Fixed in 0:12.13.0-0.20220509210748.2d090b5.el8 - Upgrade
Upgrade
redhat/python-oslo-metricsto a version that resolves this vulnerability.Fixed in 0:0.3.0-0.20220216012738.43eee50.el8 - Upgrade
Upgrade
redhat/python-oslo-middlewareto a version that resolves this vulnerability.Fixed in 0:4.5.1-0.20220509203328.2f72b30.el8 - Upgrade
Upgrade
redhat/python-oslo-policyto a version that resolves this vulnerability.Fixed in 0:3.12.1-0.20220509221328.9673a74.el8 - Upgrade
Upgrade
redhat/python-oslo-rootwrapto a version that resolves this vulnerability.Fixed in 0:6.3.1-0.20220509204453.1b1b960.el8 - Upgrade
Upgrade
redhat/python-oslo-serializationto a version that resolves this vulnerability.Fixed in 0:4.3.0-0.20220509195921.6910f75.el8 - Upgrade
Upgrade
redhat/python-oslo-serviceto a version that resolves this vulnerability.Fixed in 0:2.8.0-0.20220509203713.6552b9a.el8 - Upgrade
Upgrade
redhat/python-oslo-upgradecheckto a version that resolves this vulnerability.Fixed in 0:1.5.0-0.20220509195112.1559e03.el8 - Upgrade
Upgrade
redhat/python-oslo-utilsto a version that resolves this vulnerability.Fixed in 0:4.13.0-0.20220509213520.de4429f.el8 - Upgrade
Upgrade
redhat/python-oslo-versionedobjectsto a version that resolves this vulnerability.Fixed in 0:2.6.0-0.20220509202736.25d34d6.el8 - Upgrade
Upgrade
redhat/python-osprofilerto a version that resolves this vulnerability.Fixed in 0:3.4.3-0.20220509214403.3286301.el8 - Upgrade
Upgrade
redhat/python-os-service-typesto a version that resolves this vulnerability.Fixed in 0:1.7.0-0.20220215231659.0b2f473.el8 - Upgrade
Upgrade
redhat/python-os-traitsto a version that resolves this vulnerability.Fixed in 0:2.7.0-0.20220509205801.3d1dbf0.el8 - Upgrade
Upgrade
redhat/python-packagingto a version that resolves this vulnerability.Fixed in 0:20.4-2.el8 - Upgrade
Upgrade
redhat/python-pasteto a version that resolves this vulnerability.Fixed in 0:3.2.4-2.el8 - Upgrade
Upgrade
redhat/python-paste-deployto a version that resolves this vulnerability.Fixed in 0:2.0.1-5.el8 - Upgrade
Upgrade
redhat/python-pbrto a version that resolves this vulnerability.Fixed in 0:5.5.1-2.el8 - Upgrade
Upgrade
redhat/python-pecanto a version that resolves this vulnerability.Fixed in 0:1.3.2-10.el8 - Upgrade
Upgrade
redhat/python-pexpectto a version that resolves this vulnerability.Fixed in 0:4.6-3.el8 - Upgrade
Upgrade
redhat/python-pintto a version that resolves this vulnerability.Fixed in 0:0.10.1-3.el8 - Upgrade
Upgrade
redhat/python-proliantutilsto a version that resolves this vulnerability.Fixed in 0:2.13.2-0.20220509214147.8c7b6b1.el8 - Upgrade
Upgrade
redhat/python-pycadfto a version that resolves this vulnerability.Fixed in 0:3.1.1-0.20220215232623.4179996.el8 - Upgrade
Upgrade
redhat/python-pycdlibto a version that resolves this vulnerability.Fixed in 0:1.11.0-4.el8 - Upgrade
Upgrade
redhat/python-pynaclto a version that resolves this vulnerability.Fixed in 0:1.3.0-6.el8 - Upgrade
Upgrade
redhat/python-pyperclipto a version that resolves this vulnerability.Fixed in 0:1.6.4-7.el8 - Upgrade
Upgrade
redhat/python-pyrsistentto a version that resolves this vulnerability.Fixed in 0:0.16.0-4.el8 - Upgrade
Upgrade
redhat/python-redisto a version that resolves this vulnerability.Fixed in 0:3.3.8-2.el8 - Upgrade
Upgrade
redhat/python-repoze-lruto a version that resolves this vulnerability.Fixed in 0:0.7-7.el8 - Upgrade
Upgrade
redhat/python-requestsexceptionsto a version that resolves this vulnerability.Fixed in 0:1.4.0-0.20220215231659.d7ac0ff.el8 - Upgrade
Upgrade
redhat/python-retryingto a version that resolves this vulnerability.Fixed in 0:1.2.3-22.el8 - Upgrade
Upgrade
redhat/python-rfc3986to a version that resolves this vulnerability.Fixed in 0:1.2.0-6.el8 - Upgrade
Upgrade
redhat/python-routesto a version that resolves this vulnerability.Fixed in 0:2.4.1-12.el8 - Upgrade
Upgrade
redhat/python-scciclientto a version that resolves this vulnerability.Fixed in 0:0.11.1-0.20220216020832.a84332b.el8 - Upgrade
Upgrade
redhat/python-simplegenericto a version that resolves this vulnerability.Fixed in 0:0.8.1-18.el8 - Upgrade
Upgrade
redhat/python-simplejsonto a version that resolves this vulnerability.Fixed in 0:3.17.0-2.el8 - Upgrade
Upgrade
redhat/python-singledispatchto a version that resolves this vulnerability.Fixed in 0:3.4.0.3-19.el8 - Upgrade
Upgrade
redhat/python-sixto a version that resolves this vulnerability.Fixed in 0:1.15.0-3.el8 - Upgrade
Upgrade
redhat/python-soupsieveto a version that resolves this vulnerability.Fixed in 0:2.1.0-2.el8 - Upgrade
Upgrade
redhat/python-sqlparseto a version that resolves this vulnerability.Fixed in 0:0.2.4-10.el8 - Upgrade
Upgrade
redhat/python-statsdto a version that resolves this vulnerability.Fixed in 0:3.2.1-17.el8 - Upgrade
Upgrade
redhat/python-stevedoreto a version that resolves this vulnerability.Fixed in 0:3.5.0-0.20220509195112.442f157.el8 - Upgrade
Upgrade
redhat/python-sushyto a version that resolves this vulnerability.Fixed in 0:4.1.1-0.20220302175405.c769149.el8 - Upgrade
Upgrade
redhat/python-sushy-oem-idracto a version that resolves this vulnerability.Fixed in 0:4.0.0-0.20220324125409.7b75e6e.el8 - Upgrade
Upgrade
redhat/python-swiftclientto a version that resolves this vulnerability.Fixed in 0:3.13.1-0.20220509204112.4989d94.el8 - Upgrade
Upgrade
redhat/python-tempitato a version that resolves this vulnerability.Fixed in 0:0.5.1-25.el8 - Upgrade
Upgrade
redhat/python-tenacityto a version that resolves this vulnerability.Fixed in 0:6.2.0-2.el8 - Upgrade
Upgrade
redhat/python-toozto a version that resolves this vulnerability.Fixed in 0:2.11.1-0.20220509215238.96f91b9.el8 - Upgrade
Upgrade
redhat/python-vineto a version that resolves this vulnerability.Fixed in 0:1.3.0-5.el8 - Upgrade
Upgrade
redhat/python-voluptuousto a version that resolves this vulnerability.Fixed in 0:0.11.7-3.el8 - Upgrade
Upgrade
redhat/python-waitressto a version that resolves this vulnerability.Fixed in 0:2.0.0-2.el8 - Upgrade
Upgrade
redhat/python-warlockto a version that resolves this vulnerability.Fixed in 0:1.3.3-2.el8 - Upgrade
Upgrade
redhat/python-wcwidthto a version that resolves this vulnerability.Fixed in 0:0.1.7-15.el8 - Upgrade
Upgrade
redhat/python-webobto a version that resolves this vulnerability.Fixed in 0:1.8.5-5.el8 - Upgrade
Upgrade
redhat/python-webtestto a version that resolves this vulnerability.Fixed in 0:2.0.33-5.el8 - Upgrade
Upgrade
redhat/python-werkzeugto a version that resolves this vulnerability.Fixed in 0:2.0.3-1.el8 - Upgrade
Upgrade
redhat/python-wraptto a version that resolves this vulnerability.Fixed in 0:1.11.2-4.el8 - Upgrade
Upgrade
redhat/python-wsmeto a version that resolves this vulnerability.Fixed in 0:0.11.0-0.20220216004816.80bda90.el8 - Upgrade
Upgrade
redhat/python-yappito a version that resolves this vulnerability.Fixed in 0:1.0-3.el8 - Upgrade
Upgrade
redhat/python-zaketo a version that resolves this vulnerability.Fixed in 0:0.2.2-19.el8 - Upgrade
Upgrade
redhat/python-zeroconfto a version that resolves this vulnerability.Fixed in 0:0.24.4-2.el8 - Upgrade
Upgrade
redhat/python-zippto a version that resolves this vulnerability.Fixed in 0:0.5.1-3.el8 - Upgrade
Upgrade
redhat/openshift-serverless-clientsto a version that resolves this vulnerability.Fixed in 0:1.3.1-4.el8 - Upgrade
Upgrade
redhat/go-toolsetto a version that resolves this vulnerability.Fixed in 1.17-golang-0:1.17.12-1.el7_9 - Upgrade
Upgrade
redhat/git-lfsto a version that resolves this vulnerability.Fixed in 0:2.13.3-3.el8_6 - Upgrade
Upgrade
redhat/grafanato a version that resolves this vulnerability.Fixed in 0:7.5.15-3.el8 - Upgrade
Upgrade
redhat/grafana-pcpto a version that resolves this vulnerability.Fixed in 0:3.2.0-2.el8 - Upgrade
Upgrade
redhat/golangto a version that resolves this vulnerability.Fixed in 0:1.17.12-1.el9_0 - Upgrade
Upgrade
redhat/grafanato a version that resolves this vulnerability.Fixed in 0:7.5.15-3.el9 - Upgrade
Upgrade
redhat/toolboxto a version that resolves this vulnerability.Fixed in 0:0.0.99.3-5.el9 - Upgrade
Upgrade
redhat/grafana-pcpto a version that resolves this vulnerability.Fixed in 0:3.2.0-3.el9 - Upgrade
Upgrade
redhat/git-lfsto a version that resolves this vulnerability.Fixed in 0:3.2.0-1.el9 - Upgrade
Upgrade
redhat/atomic-openshift-service-idlerto a version that resolves this vulnerability.Fixed in 0:4.11.0-202206222028.p0.g39cfc66.assembly.stream.el8 - Upgrade
Upgrade
redhat/buildahto a version that resolves this vulnerability.Fixed in 1:1.23.4-2.el8 - Upgrade
Upgrade
redhat/butaneto a version that resolves this vulnerability.Fixed in 0:0.15.0-1.rhaos4.11.el8 - Upgrade
Upgrade
redhat/conmonto a version that resolves this vulnerability.Fixed in 2:2.1.2-2.rhaos4.11.el8 - Upgrade
Upgrade
redhat/console-login-helper-messagesto a version that resolves this vulnerability.Fixed in 0:0.20.3-2.rhaos4.11.el8 - Upgrade
Upgrade
redhat/containernetworking-pluginsto a version that resolves this vulnerability.Fixed in 0:1.0.1-5.rhaos4.11.el8 - Upgrade
Upgrade
redhat/containers-commonto a version that resolves this vulnerability.Fixed in 2:1-21.rhaos4.11.el8 - Upgrade
Upgrade
redhat/container-selinuxto a version that resolves this vulnerability.Fixed in 2:2.188.0-1.rhaos4.11.el8 - Upgrade
Upgrade
redhat/coreos-installerto a version that resolves this vulnerability.Fixed in 0:0.15.0-2.rhaos4.11.el8 - Upgrade
Upgrade
redhat/cri-oto a version that resolves this vulnerability.Fixed in 0:1.24.1-11.rhaos4.11.gitb0d2ef3.el8 - Upgrade
Upgrade
redhat/cri-toolsto a version that resolves this vulnerability.Fixed in 0:1.24.2-4.1.el8 - Upgrade
Upgrade
redhat/criuto a version that resolves this vulnerability.Fixed in 0:3.15-4.rhaos4.11.el8 - Upgrade
Upgrade
redhat/crunto a version that resolves this vulnerability.Fixed in 0:1.4.2-1.rhaos4.11.el8 - Upgrade
Upgrade
redhat/fuse-overlayfsto a version that resolves this vulnerability.Fixed in 0:1.9-1.rhaos4.11.el8 - Upgrade
Upgrade
redhat/haproxyto a version that resolves this vulnerability.Fixed in 0:2.2.24-1.el8 - Upgrade
Upgrade
redhat/ignitionto a version that resolves this vulnerability.Fixed in 0:2.14.0-3.rhaos4.11.el8 - Upgrade
Upgrade
redhat/kata-containersto a version that resolves this vulnerability.Fixed in 0:2.4.2-1.el8 - Upgrade
Upgrade
redhat/libslirpto a version that resolves this vulnerability.Fixed in 0:4.4.0-2.rhaos4.11.el8 - Upgrade
Upgrade
redhat/openshiftto a version that resolves this vulnerability.Fixed in 0:4.11.0-202207082037.p0.g9546431.assembly.stream.el8 - Upgrade
Upgrade
redhat/openshift-ansibleto a version that resolves this vulnerability.Fixed in 0:4.11.0-202206240216.p0.g9de1722.assembly.stream.el8 - Upgrade
Upgrade
redhat/openshift-clientsto a version that resolves this vulnerability.Fixed in 0:4.11.0-202207291716.p0.g7075089.assembly.stream.el8 - Upgrade
Upgrade
redhat/openshift-kuryrto a version that resolves this vulnerability.Fixed in 0:4.11.0-202206232036.p0.g66c0cec.assembly.stream.el8 - Upgrade
Upgrade
redhat/openvswitch2.17to a version that resolves this vulnerability.Fixed in 0:2.17.0-22.el8fd - Upgrade
Upgrade
redhat/ovn22.03to a version that resolves this vulnerability.Fixed in 0:22.03.0-37.el8fd - Upgrade
Upgrade
redhat/ovn22.06to a version that resolves this vulnerability.Fixed in 0:22.06.0-27.el8fd - Upgrade
Upgrade
redhat/podmanto a version that resolves this vulnerability.Fixed in 2:4.0.2-6.rhaos4.11.el8 - Upgrade
Upgrade
redhat/runcto a version that resolves this vulnerability.Fixed in 3:1.1.2-1.rhaos4.11.el8 - Upgrade
Upgrade
redhat/rust-afterburnto a version that resolves this vulnerability.Fixed in 0:5.3.0-1.rhaos4.11.el8 - Upgrade
Upgrade
redhat/rust-bootupdto a version that resolves this vulnerability.Fixed in 0:0.2.5-3.rhaos4.11.el8 - Upgrade
Upgrade
redhat/skopeoto a version that resolves this vulnerability.Fixed in 2:1.5.2-3.rhaos4.11.el8 - Upgrade
Upgrade
redhat/slirp4netnsto a version that resolves this vulnerability.Fixed in 0:1.1.8-1.rhaos4.11.el8 - Upgrade
Upgrade
redhat/toolboxto a version that resolves this vulnerability.Fixed in 0:0.0.9-1.rhaos4.11.el8 - Upgrade
Upgrade
redhat/cri-oto a version that resolves this vulnerability.Fixed in 0:1.24.3-6.rhaos4.11.gitc4567c0.el8 - Upgrade
Upgrade
redhat/cri-toolsto a version that resolves this vulnerability.Fixed in 0:1.24.2-7.el8 - Upgrade
Upgrade
redhat/butaneto a version that resolves this vulnerability.Fixed in 0:0.16.0-2.rhaos4.12.el8 - Upgrade
Upgrade
redhat/ignitionto a version that resolves this vulnerability.Fixed in 0:2.14.0-5.rhaos4.12.el8 - Upgrade
Upgrade
redhat/etcdto a version that resolves this vulnerability.Fixed in 0:3.3.23-12.el8 - Upgrade
Upgrade
redhat/kubevirtto a version that resolves this vulnerability.Fixed in 0:4.12.0-1057.el7 - Upgrade
Upgrade
redhat/kubevirtto a version that resolves this vulnerability.Fixed in 0:4.12.0-1057.el8 - Upgrade
Upgrade
debian/golang-1.19to a version that resolves this vulnerability.Fixed in 1.19.8-2 - Upgrade
Upgrade
redhat/golangto a version that resolves this vulnerability.Fixed in 1.18.4 - Upgrade
Upgrade
redhat/golangto a version that resolves this vulnerability.Fixed in 1.17.12 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.18.5-1 - Upgrade
Upgrade
golang (net/http)to a version that resolves this vulnerability.Fixed in 1.17.12 - Upgrade
Upgrade
golang (net/http)to a version that resolves this vulnerability.Fixed in 1.18.4
Event History
Parent advisories
This vulnerability appears in the following advisories.
- RHSA-2022:6113
- RHSA-2022:5068
- RHSA-2022:6183
- RHSA-2022:6345
- RHSA-2022:6187
- RHSA-2022:6188
- RHSA-2022:6430
- RHSA-2023:1042
- RHSA-2023:3664
- RHSA-2022:6040
- RHSA-2022:6042
- RHSA-2022:6152
- RHSA-2022:6348
- RHSA-2022:6346
- RHSA-2022:6347
- RHSA-2022:6370
- RHSA-2023:3642
- RHSA-2022:5866
- RHSA-2022:5775
- RHSA-2022:7129
- RHSA-2022:7519
- RHSA-2022:7529
- RHSA-2022:7648
- RHSA-2023:2758
- RHSA-2023:2802
- RHSA-2022:5799
- RHSA-2022:8057
- RHSA-2022:8098
- RHSA-2022:8250
- RHSA-2023:2357
- RHSA-2022:9047
- RHSA-2022:8626
- RHSA-2022:7398
- RHSA-2022:7399
- RHSA-2022:6283
- RHSA-2023:1275
- RHSA-2023:0407
- RHSA-2023:0408
- RHSA-2022:6344
- RHSA-2023:1529
- IBM-7249999
Frequently Asked Questions
What is the severity of CVE-2022-1705?
CVE-2022-1705 is classified as a medium-severity vulnerability.
How do I fix CVE-2022-1705?
To mitigate CVE-2022-1705, upgrade to the corrected versions specified in your affected software release.
What components are affected by CVE-2022-1705?
CVE-2022-1705 affects various packages such as skupper-cli, libsodium, and openstack-ironic, among others.
What type of vulnerability is CVE-2022-1705?
CVE-2022-1705 is a request smuggling vulnerability related to improper handling of Transfer-Encoding headers.
Can CVE-2022-1705 be exploited without an intermediary server?
Exploitation of CVE-2022-1705 requires an intermediate server that improperly accepts the invalid Transfer-Encoding header.