Описание
guzzlehttp/psr7 is a PSR-7 HTTP message library. Versions prior to 1.8.4 and 2.1.1 are vulnerable to improper header parsing. An attacker could sneak in a new line character and pass untrusted values. The issue is patched in 1.8.4 and 2.1.1. There are currently no known workarounds.
Релиз | Статус | Примечание |
---|---|---|
devel | not-affected | 2.6.2-1 |
esm-apps/focal | released | 1.4.2-0.1+deb10u2build0.20.04.1 |
esm-apps/jammy | released | 1.8.3-1ubuntu0.1~esm1 |
esm-apps/noble | not-affected | 2.6.2-1 |
esm-apps/xenial | ignored | backporting risks regressions |
focal | released | 1.4.2-0.1+deb10u2build0.20.04.1 |
impish | ignored | end of life |
jammy | needed | |
kinetic | ignored | end of life, was needs-triage |
lunar | ignored | end of life, was needs-triage |
Показывать по
Ссылки на источники
EPSS
5 Medium
CVSS2
7.5 High
CVSS3
Связанные уязвимости
guzzlehttp/psr7 is a PSR-7 HTTP message library. Versions prior to 1.8.4 and 2.1.1 are vulnerable to improper header parsing. An attacker could sneak in a new line character and pass untrusted values. The issue is patched in 1.8.4 and 2.1.1. There are currently no known workarounds.
guzzlehttp/psr7 is a PSR-7 HTTP message library. Versions prior to 1.8 ...
Уязвимость библиотеки обработки HTTP-сообщений PSR-7 guzzlehttp/psr7, связанная с недостаточной проверкой входных данных, позволяющая нарушителю оказать воздействие на целостность защищаемой информации
EPSS
5 Medium
CVSS2
7.5 High
CVSS3