Security Advisory

CVE-2021-33195

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2021-08-02 18:51:34
Last updated 2024-08-03 23:42:20
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Go before 1.15.13 and 1.16.x before 1.16.5 has functions for DNS lookups that do not validate replies from DNS servers, and thus a return value may contain an unsafe injection (e.g., XSS) that does not conform to the RFC1035 format.