Arbitrary Header Injection in Go ReverseProxy Configuration
CVE-2021-33197
5.3MEDIUM
What is CVE-2021-33197?
Older versions of Go, specifically prior to 1.15.13 and 1.16.x before 1.16.5, present a vulnerability in the ReverseProxy component from the net/http/httputil package. This vulnerability allows an attacker to manipulate and inject arbitrary headers based on specific configurations of ReverseProxy, potentially enabling further attacks or unauthorized access to system resources.