Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-1000164

Опубликовано: 17 мар. 2016
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers vulnerability in "process_headers" function in "gunicorn/http/wsgi.py" that can result in an attacker causing the server to return arbitrary HTTP headers. This vulnerability appears to have been fixed in 19.5.0.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7python-gunicornWill not fix
Red Hat OpenStack Platform 12 (Pike)python-gunicornNot affected
Red Hat OpenStack Platform 13 (Queens)python-gunicornNot affected
Red Hat Storage Console 2python-gunicornWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-113
https://bugzilla.redhat.com/show_bug.cgi?id=1564940python-gunicorn: Improper neutralization of CRLF Sequences http/wsgi.py:process_headers() can allow an attacker to cause a server to return arbitrary HTTP headers

EPSS

Процентиль: 81%
0.01484
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 8 лет назад

gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers vulnerability in "process_headers" function in "gunicorn/http/wsgi.py" that can result in an attacker causing the server to return arbitrary HTTP headers. This vulnerability appears to have been fixed in 19.5.0.

CVSS3: 7.5
nvd
почти 8 лет назад

gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers vulnerability in "process_headers" function in "gunicorn/http/wsgi.py" that can result in an attacker causing the server to return arbitrary HTTP headers. This vulnerability appears to have been fixed in 19.5.0.

CVSS3: 7.5
debian
почти 8 лет назад

gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of ...

suse-cvrf
почти 8 лет назад

Security update for python-gunicorn, python3-gunicorn

CVSS3: 7.5
github
больше 7 лет назад

Gunicorn contains Improper Neutralization of CRLF sequences in HTTP headers

EPSS

Процентиль: 81%
0.01484
Низкий

5.3 Medium

CVSS3