CVE-2021-33197
Jenkins vulnerability analysis and mitigation

Overview

A vulnerability was identified in Go versions before 1.15.13 and 1.16.x before 1.16.5, affecting the ReverseProxy functionality in the net/http/httputil package. The vulnerability was assigned CVE-2021-33197 and was disclosed in June 2021 (Golang Announce).

Technical details

The vulnerability exists in the ReverseProxy component where certain configurations could allow an attacker to forward specific hop-by-hop headers, including Connection headers, if the first one was empty. This becomes particularly dangerous when the target of the ReverseProxy is itself a reverse proxy, as it would enable an attacker to drop arbitrary headers, including those set by the ReverseProxy.Director (Golang Announce).

Impact

When exploited, this vulnerability allows attackers to manipulate HTTP headers by dropping arbitrary headers in certain proxy configurations. This could potentially lead to security bypass or header manipulation attacks, particularly in multi-proxy setups (Red Hat CVE).

Mitigation and workarounds

The vulnerability has been fixed in Go versions 1.15.13 and 1.16.5. Users are advised to upgrade to these or later versions to address the security issue. The fix prevents the unintended forwarding of connection headers in reverse proxy configurations (Golang Announce).

Additional resources


SourceThis report was generated using AI

Related Jenkins vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-67635HIGH7.5
  • JavaJava
  • cpe:2.3:a:jenkins:jenkins
NoYesDec 10, 2025
CVE-2025-67638MEDIUM4.3
  • JavaJava
  • jenkins
NoYesDec 10, 2025
CVE-2025-67637MEDIUM4.3
  • JavaJava
  • jenkins-2.528
NoYesDec 10, 2025
CVE-2025-67636MEDIUM4.3
  • JavaJava
  • org.jenkins-ci.main:jenkins-core
NoYesDec 10, 2025
CVE-2025-67639LOW3.5
  • JavaJava
  • cpe:2.3:a:jenkins:jenkins
NoYesDec 10, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management