Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7v2r-wxmg-mgvc

Опубликовано: 25 авг. 2021
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

HTTP Request smuggling in tiny_http

HTTP pipelining issues and request smuggling attacks are possible due to incorrect Transfer encoding header parsing. It is possible conduct HTTP request smuggling attacks (CL:TE/TE:TE) by sending invalid Transfer Encoding headers. By manipulating the HTTP response the attacker could poison a web-cache, perform an XSS attack, or obtain sensitive information from requests other than their own.

Пакеты

Наименование

tiny_http

rust
Затронутые версииВерсия исправления

< 0.8.0

0.8.0

EPSS

Процентиль: 47%
0.00239
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-444

Связанные уязвимости

CVSS3: 6.5
nvd
около 5 лет назад

An issue was discovered in the tiny_http crate through 2020-06-16 for Rust. HTTP Request smuggling can occur via a malformed Transfer-Encoding header.

EPSS

Процентиль: 47%
0.00239
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-444