go/src
Roberto Clapis 8fcee8abbe [release-branch.go1.14-security] net/http/cgi,net/http/fcgi: add Content-Type detection
This CL ensures that responses served via CGI and FastCGI
have a Content-Type header based on the content of the
response if not explicitly set by handlers.

If the implementers of the handler did not explicitly
specify a Content-Type both CGI implementations would default
to "text/html", potentially causing cross-site scripting.

Thanks to RedTeam Pentesting GmbH for reporting this.

Fixes CVE-2020-24553

Change-Id: I82cfc396309b5ab2e8d6e9a87eda8ea7e3799473
Reviewed-on: https://team-review.git.corp.google.com/c/golang/go-private/+/823217
Reviewed-by: Russ Cox <rsc@google.com>
(cherry picked from commit 23d675d07fdc56aafd67c0a0b63d5b7e14708ff0)
Reviewed-on: https://team-review.git.corp.google.com/c/golang/go-private/+/835312
Reviewed-by: Dmitri Shuralyov <dmitshur@google.com>
2020-09-01 12:31:38 +00:00
..
archive
bufio
builtin
bytes
cmd [release-branch.go1.14] testing: capture testname on --- PASS and --- FAIL lines 2020-07-16 18:22:52 +00:00
compress
container
context
crypto [release-branch.go1.14-security] crypto/x509: respect VerifyOptions.KeyUsages on Windows 2020-07-14 12:24:21 +00:00
database/sql [release-branch.go1.14] database/sql: backport 5 Tx rollback related CLs 2020-07-16 00:35:30 +00:00
debug
encoding [release-branch.go1.14-security] encoding/binary: read at most MaxVarintLen64 bytes in ReadUvarint 2020-08-06 13:03:14 +00:00
errors
expvar
flag
fmt
go [release-branch.go1.14] cmd/doc: fix merging comments in -src mode 2020-05-28 23:17:18 +00:00
hash [release-branch.go1.14] hash/maphash: don't discard data on random seed init 2020-02-24 15:47:07 +00:00
html html: update URL in comment 2020-01-13 07:00:18 +00:00
image
index/suffixarray
internal [release-branch.go1.14] os/exec: use environment variables for user token when present 2020-03-29 17:15:56 +00:00
io
log
math [release-branch.go1.14] math/big: correct off-by-one access in divBasic 2020-04-27 16:42:55 +00:00
mime
net [release-branch.go1.14-security] net/http/cgi,net/http/fcgi: add Content-Type detection 2020-09-01 12:31:38 +00:00
os [release-branch.go1.14] syscall: preserve Windows file permissions for O_CREAT|O_TRUNC 2020-05-23 21:08:37 +00:00
path
plugin
reflect [release-branch.go1.14] reflect: zero stack slots before writing to them with write barriers 2020-07-11 02:49:14 +00:00
regexp
runtime [release-branch.go1.14] reflect: zero stack slots before writing to them with write barriers 2020-07-11 02:49:14 +00:00
sort
strconv strconv: stop describing Unicode graphic characters as non-ASCII 2020-01-26 20:38:34 +00:00
strings strings: update Join parameter name for clarity 2020-01-15 04:21:28 +00:00
sync
syscall [release-branch.go1.14] syscall: preserve Windows file permissions for O_CREAT|O_TRUNC 2020-05-23 21:08:37 +00:00
testdata
testing [release-branch.go1.14] testing: capture testname on --- PASS and --- FAIL lines 2020-07-16 18:22:52 +00:00
text text/template/parse: remove redundant return 2020-01-23 23:07:10 +00:00
time [release-branch.go1.14] runtime: don't panic on racy use of timers 2020-02-27 23:15:33 +00:00
unicode all: fix typo in RuneSelf, runeSelf comments 2020-01-06 02:46:02 +00:00
unsafe
vendor std,cmd: sync go.mod with new release branches 2020-02-01 06:01:05 +00:00
Make.dist
README.vendor
all.bash
all.bat
all.rc
bootstrap.bash
buildall.bash
clean.bash
clean.bat
clean.rc
cmp.bash
go.mod std,cmd: sync go.mod with new release branches 2020-02-01 06:01:05 +00:00
go.sum std,cmd: sync go.mod with new release branches 2020-02-01 06:01:05 +00:00
iostest.bash
make.bash
make.bat
make.rc
race.bash
race.bat
run.bash
run.bat
run.rc

README.vendor

Vendoring in std and cmd
========================

The Go command maintains copies of external packages needed by the
standard library in the src/vendor and src/cmd/vendor directories.

In GOPATH mode, imports of vendored packages are resolved to these
directories following normal vendor directory logic
(see golang.org/s/go15vendor).

In module mode, std and cmd are modules (defined in src/go.mod and
src/cmd/go.mod). When a package outside std or cmd is imported
by a package inside std or cmd, the import path is interpreted
as if it had a "vendor/" prefix. For example, within "crypto/tls",
an import of "golang.org/x/crypto/cryptobyte" resolves to
"vendor/golang.org/x/crypto/cryptobyte". When a package with the
same path is imported from a package outside std or cmd, it will
be resolved normally. Consequently, a binary may be built with two
copies of a package at different versions if the package is
imported normally and vendored by the standard library.

Vendored packages are internally renamed with a "vendor/" prefix
to preserve the invariant that all packages have distinct paths.
This is necessary to avoid compiler and linker conflicts. Adding
a "vendor/" prefix also maintains the invariant that standard
library packages begin with a dotless path element.

The module requirements of std and cmd do not influence version
selection in other modules. They are only considered when running
module commands like 'go get' and 'go mod vendor' from a directory
in GOROOT/src.

Maintaining vendor directories
==============================

Before updating vendor directories, ensure that module mode is enabled.
Make sure GO111MODULE=off is not set ('on' or 'auto' should work).

Requirements may be added, updated, and removed with 'go get'.
The vendor directory may be updated with 'go mod vendor'.
A typical sequence might be:

    cd src
    go get -d golang.org/x/net@latest
    go mod tidy
    go mod vendor

Use caution when passing '-u' to 'go get'. The '-u' flag updates
modules providing all transitively imported packages, not only
the module providing the target package.

Note that 'go mod vendor' only copies packages that are transitively
imported by packages in the current module. If a new package is needed,
it should be imported before running 'go mod vendor'.