Описание
guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Set-Cookie header fields with no size restrictions. Attackers can return many large cookies from a malicious server, causing Guzzle to store excessive data in memory and generate oversized Cookie headers that fail in handlers or destination servers.
A flaw was found in guzzlehttp/guzzle. A remote attacker can exploit this vulnerability by sending an excessive number of large 'Set-Cookie' header fields from a malicious server. This causes the application's CookieJar to store an unbounded amount of data in memory, leading to resource exhaustion. The consequence is a Denial of Service (DoS), where the application becomes unresponsive or crashes due to excessive memory consumption and oversized cookie headers.
Отчет
Community packages in Fedora and EPEL that bundle guzzlehttp/guzzle (nextcloud, roundcubemail) already ship patched versions (7.15.2 and 7.15.3 respectively) that include the fix for this vulnerability, and are therefore not affected.
Меры по смягчению последствий
Upgrade guzzlehttp/guzzle to version 7.15.1 or later.
Дополнительная информация
Статус:
5.3 Medium
CVSS3
Связанные уязвимости
guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Set-Cookie header fields with no size restrictions. Attackers can return many large cookies from a malicious server, causing Guzzle to store excessive data in memory and generate oversized Cookie headers that fail in handlers or destination servers.
guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Set-Cookie header fields with no size restrictions. Attackers can return many large cookies from a malicious server, causing Guzzle to store excessive data in memory and generate oversized Cookie headers that fail in handlers or destination servers.
guzzlehttp/guzzle versions before 7.15.1 contain a denial of service v ...
Guzzle: Unbounded response cookies risk denial of service
5.3 Medium
CVSS3