Описание
agoo prior to 2.14.0 allows request smuggling attacks where agoo is used as a backend and a frontend proxy also being vulnerable. HTTP pipelining issues and request smuggling attacks might be possible due to incorrect Content-Length and Transfer encoding header parsing. It is possible to conduct HTTP request smuggling attacks where agoo is used as part of a chain of backend servers due to insufficient Content-Length and Transfer Encoding parsing.
Ссылки
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.12.3 (включая)
cpe:2.3:a:ohler:agoo:*:*:*:*:*:ruby:*:*
EPSS
Процентиль: 52%
0.00289
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-444
Связанные уязвимости
EPSS
Процентиль: 52%
0.00289
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-444