Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-29361

Опубликовано: 25 мая 2022
Источник: redhat
EPSS Средний

Описание

Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perform HTTP Request Smuggling using a crafted HTTP request with multiple requests included inside the body. NOTE: the vendor's position is that this behavior can only occur in unsupported configurations involving development mode and an HTTP server from outside the Werkzeug project

Отчет

Red Hat Product Security does not consider this to be a vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 5python-werkzeugNot affected
Red Hat Ceph Storage 6python-werkzeugNot affected
Red Hat Enterprise Linux 7python-werkzeugNot affected
Red Hat Enterprise Linux 8python-werkzeugNot affected
Red Hat OpenShift Container Platform 4python-werkzeugNot affected
Red Hat OpenStack Platform 16.1python-werkzeugNot affected
Red Hat OpenStack Platform 16.2python-werkzeugNot affected
Red Hat OpenStack Platform 17.1python-werkzeugNot affected
Red Hat OpenStack Platform 18.0python-werkzeugNot affected
Red Hat Storage 3python-werkzeugNot affected

Показывать по

Дополнительная информация

Дефект:
CWE-444
https://bugzilla.redhat.com/show_bug.cgi?id=2253045python-Werkzeug: HTTP Request Smuggling

EPSS

Процентиль: 97%
0.31113
Средний

Связанные уязвимости

CVSS3: 9.8
nvd
больше 3 лет назад

Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perform HTTP Request Smuggling using a crafted HTTP request with multiple requests included inside the body. NOTE: the vendor's position is that this behavior can only occur in unsupported configurations involving development mode and an HTTP server from outside the Werkzeug project

CVSS3: 9.8
debian
больше 3 лет назад

Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below ...

github
больше 3 лет назад

Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perform HTTP Request Smuggling using a crafted HTTP request with multiple requests included inside the body.

CVSS3: 9.8
fstec
почти 4 года назад

Уязвимость библиотеки веб-приложений Pallets Werkzeug, связанная с недостатками обработки HTTP-запросов, позволяющая нарушителю провести атаку межсайтового скриптинга (XSS)

EPSS

Процентиль: 97%
0.31113
Средний