This bug was fixed in the package golang-1.10 - 1.10.4-2ubuntu1~18.04.2 --------------- golang-1.10 (1.10.4-2ubuntu1~18.04.2) bionic-security; urgency=medium
* SECURITY UPDATE: XSS (LP: #1914372) - debian/patches/CVE-2020-24553.patch: Add Content-Type detection in net/http/cgi and net/http/fcgi. - CVE-2020-24553 -- Dariusz Gadomski <dgadom...@ubuntu.com> Wed, 03 Feb 2021 08:42:42 +0100 ** Changed in: golang-1.10 (Ubuntu Bionic) Status: In Progress => Fix Released ** Changed in: golang-1.10 (Ubuntu Xenial) Status: In Progress => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1914372 Title: Ubuntu packages affected by CVE-2020-24553 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/golang-1.14/+bug/1914372/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs