« Volver al listado

CVE-2023-45286

Estado: ModificadaMedia (5.9)—

A race condition in go-resty can result in HTTP request body disclosure across requests. This condition can be triggered by calling sync.Pool.Put with the same *bytes.Buffer more than once, when request retries are enabled and a retry occurs. The call to sync.Pool.Get will then return a bytes.Buffer that hasn't had bytes.Buffer.Reset called on it. This dirty buffer will contain the HTTP request body from an unrelated request, and go-resty will append the current HTTP request body to it, sending two bodies in one request. The sync.Pool in question is defined at package level scope, so a completely unrelated server could receive the request body.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-45286",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-45286",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-08-28T20:00:00.708483Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.9,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.2
      }
    ]
  },
  "affected": [
    {
      "source": "security@golang.org",
      "affectedData": [
        {
          "vendor": "github.com/go-resty/resty/v2",
          "product": "github.com/go-resty/resty/v2",
          "versions": [
            {
              "status": "affected",
              "version": "2.10.0",
              "lessThan": "2.11.0",
              "versionType": "semver"
            }
          ],
          "packageName": "github.com/go-resty/resty/v2",
          "collectionURL": "https://pkg.go.dev",
          "defaultStatus": "unaffected",
          "programRoutines": [
            {
              "name": "handleRequestBody"
            },
            {
              "name": "Backoff"
            },
            {
              "name": "Request.Delete"
            },
            {
              "name": "Request.Execute"
            },
            {
              "name": "Request.Get"
            },
            {
              "name": "Request.Head"
            },
            {
              "name": "Request.Options"
            },
            {
              "name": "Request.Patch"
            },
            {
              "name": "Request.Post"
            },
            {
              "name": "Request.Put"
            },
            {
              "name": "Request.Send"
            }
          ]
        }
      ]
    }
  ],
  "published": "2023-11-28T17:15:08.280",
  "references": [
    {
      "url": "https://github.com/go-resty/resty/commit/577fed8730d79f583eb48dfc81674164e1fc471e",
      "source": "security@golang.org"
    },
    {
      "url": "https://github.com/go-resty/resty/issues/739",
      "tags": [
        "Exploit",
        "Issue Tracking"
      ],
      "source": "security@golang.org"
    },
    {
      "url": "https://github.com/go-resty/resty/issues/743",
      "tags": [
        "Issue Tracking"
      ],
      "source": "security@golang.org"
    },
    {
      "url": "https://github.com/go-resty/resty/pull/745",
      "tags": [
        "Issue Tracking",
        "Patch"
      ],
      "source": "security@golang.org"
    },
    {
      "url": "https://pkg.go.dev/vuln/GO-2023-2328",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@golang.org"
    },
    {
      "url": "https://github.com/go-resty/resty/commit/577fed8730d79f583eb48dfc81674164e1fc471e",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/go-resty/resty/issues/739",
      "tags": [
        "Exploit",
        "Issue Tracking"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/go-resty/resty/issues/743",
      "tags": [
        "Issue Tracking"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/go-resty/resty/pull/745",
      "tags": [
        "Issue Tracking",
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://pkg.go.dev/vuln/GO-2023-2328",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-362"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A race condition in go-resty can result in HTTP request body disclosure across requests. This condition can be triggered by calling sync.Pool.Put with the same *bytes.Buffer more than once, when request retries are enabled and a retry occurs. The call to sync.Pool.Get will then return a bytes.Buffer that hasn't had bytes.Buffer.Reset called on it. This dirty buffer will contain the HTTP request body from an unrelated request, and go-resty will append the current HTTP request body to it, sending two bodies in one request. The sync.Pool in question is defined at package level scope, so a completely unrelated server could receive the request body."
    },
    {
      "lang": "es",
      "value": "Una condición de ejecución en go-resty puede dar como resultado la divulgación del cuerpo de la solicitud HTTP entre solicitudes. Esta condición se puede desencadenar llamando a sync.Pool.Put con el mismo *bytes.Buffer más de una vez, cuando los reintentos de solicitud están habilitados y se produce un reintento. La llamada a sync.Pool.Get devolverá un bytes.Buffer al que no se le ha llamado bytes.Buffer.Reset. Este búfer sucio contendrá el cuerpo de la solicitud HTTP de una solicitud no relacionada, y go-resty le agregará el cuerpo de la solicitud HTTP actual, enviando dos cuerpos en una solicitud. El sync.Pool en cuestión se define a nivel de paquete, por lo que un servidor completamente ajeno podría recibir el cuerpo de la solicitud."
    }
  ],
  "lastModified": "2026-06-17T06:28:35.330",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:resty_project:resty:*:*:*:*:*:go:*:*",
              "vulnerable": true,
              "matchCriteriaId": "433974E8-CB64-4BBB-BB5A-9F072275B86F",
              "versionEndIncluding": "2.10.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@golang.org"
}