https://seclists.org/oss-sec/2024/q2/38: Go 1.22.2 and 1.21.9 (CVE-2023-45288 HTTP/2 CONTINUATION issue)
Published Apr 5, 2024
·Updated
Affected Software
1 affected component
go Go>=1.21.9<=1.22.2
Frequently Asked Questions
1
What is the severity of CVE-2023-45288?
CVE-2023-45288 has been rated as a moderate severity vulnerability.
2
How do I fix CVE-2023-45288?
To resolve CVE-2023-45288, upgrade to Go versions 1.22.3 or 1.21.10 or later.
3
What systems are affected by CVE-2023-45288?
CVE-2023-45288 affects Go versions 1.22.2 and 1.21.9 and their earlier releases.
4
What does CVE-2023-45288 exploit?
CVE-2023-45288 exploits a vulnerability in HTTP/2 handling within specific versions of Go.
5
Is CVE-2023-45288 critical for all users of Go?
CVE-2023-45288 may not be critical for all users but could lead to potential denial-of-service scenarios under certain conditions.