Описание
In Ktor before 1.3.0, request smuggling is possible when running behind a proxy that doesn't handle Content-Length and Transfer-Encoding properly or doesn't handle \n as a headers separator.
Ссылки
- PatchThird Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.3.0 (исключая)
cpe:2.3:a:jetbrains:ktor:*:*:*:*:*:*:*:*
EPSS
Процентиль: 0%
0.00004
Низкий
5.4 Medium
CVSS3
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-444
CWE-444
Связанные уязвимости
CVSS3: 5.4
github
около 6 лет назад
Request smuggling is possible when both chunked TE and content length specified
EPSS
Процентиль: 0%
0.00004
Низкий
5.4 Medium
CVSS3
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-444
CWE-444