Логотип exploitDog
bind:"CVE-2022-31081"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2022-31081"

Количество 8

Количество 8

ubuntu логотип

CVE-2022-31081

больше 3 лет назад

HTTP::Daemon is a simple http server class written in perl. Versions prior to 6.15 are subject to a vulnerability which could potentially be exploited to gain privileged access to APIs or poison intermediate caches. It is uncertain how large the risks are, most Perl based applications are served on top of Nginx or Apache, not on the `HTTP::Daemon`. This library is commonly used for local development and tests. Users are advised to update to resolve this issue. Users unable to upgrade may add additional request handling logic as a mitigation. After calling `my $rqst = $conn->get_request()` one could inspect the returned `HTTP::Request` object. Querying the 'Content-Length' (`my $cl = $rqst->header('Content-Length')`) will show any abnormalities that should be dealt with by a `400` response. Expected strings of 'Content-Length' SHOULD consist of either a single non-negative integer, or, a comma separated repetition of that number. (that is `42` or `42, 42, 42`). Anything else MUST be ...

CVSS3: 7.3
EPSS: Низкий
redhat логотип

CVE-2022-31081

больше 3 лет назад

HTTP::Daemon is a simple http server class written in perl. Versions prior to 6.15 are subject to a vulnerability which could potentially be exploited to gain privileged access to APIs or poison intermediate caches. It is uncertain how large the risks are, most Perl based applications are served on top of Nginx or Apache, not on the `HTTP::Daemon`. This library is commonly used for local development and tests. Users are advised to update to resolve this issue. Users unable to upgrade may add additional request handling logic as a mitigation. After calling `my $rqst = $conn->get_request()` one could inspect the returned `HTTP::Request` object. Querying the 'Content-Length' (`my $cl = $rqst->header('Content-Length')`) will show any abnormalities that should be dealt with by a `400` response. Expected strings of 'Content-Length' SHOULD consist of either a single non-negative integer, or, a comma separated repetition of that number. (that is `42` or `42, 42, 42`). Anything else MUST be ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2022-31081

больше 3 лет назад

HTTP::Daemon is a simple http server class written in perl. Versions prior to 6.15 are subject to a vulnerability which could potentially be exploited to gain privileged access to APIs or poison intermediate caches. It is uncertain how large the risks are, most Perl based applications are served on top of Nginx or Apache, not on the `HTTP::Daemon`. This library is commonly used for local development and tests. Users are advised to update to resolve this issue. Users unable to upgrade may add additional request handling logic as a mitigation. After calling `my $rqst = $conn->get_request()` one could inspect the returned `HTTP::Request` object. Querying the 'Content-Length' (`my $cl = $rqst->header('Content-Length')`) will show any abnormalities that should be dealt with by a `400` response. Expected strings of 'Content-Length' SHOULD consist of either a single non-negative integer, or, a comma separated repetition of that number. (that is `42` or `42, 42, 42`). Anything else MUST be rej

CVSS3: 7.3
EPSS: Низкий
debian логотип

CVE-2022-31081

больше 3 лет назад

HTTP::Daemon is a simple http server class written in perl. Versions p ...

CVSS3: 7.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:2874-1

больше 3 лет назад

Security update for perl-HTTP-Daemon

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:2872-1

больше 3 лет назад

Security update for perl-HTTP-Daemon

EPSS: Низкий
fstec логотип

BDU:2022-05817

больше 3 лет назад

Уязвимость демона HTTP-сервера HTTP Daemon, связанная с непоследовательной интерпритацией HTTP-запросов, позволяющая нарушителю повысить свои привилегии

CVSS3: 7.3
EPSS: Низкий
redos логотип

ROS-20240816-03

больше 1 года назад

Уязвимость perl-HTTP-Daemon

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-31081

HTTP::Daemon is a simple http server class written in perl. Versions prior to 6.15 are subject to a vulnerability which could potentially be exploited to gain privileged access to APIs or poison intermediate caches. It is uncertain how large the risks are, most Perl based applications are served on top of Nginx or Apache, not on the `HTTP::Daemon`. This library is commonly used for local development and tests. Users are advised to update to resolve this issue. Users unable to upgrade may add additional request handling logic as a mitigation. After calling `my $rqst = $conn->get_request()` one could inspect the returned `HTTP::Request` object. Querying the 'Content-Length' (`my $cl = $rqst->header('Content-Length')`) will show any abnormalities that should be dealt with by a `400` response. Expected strings of 'Content-Length' SHOULD consist of either a single non-negative integer, or, a comma separated repetition of that number. (that is `42` or `42, 42, 42`). Anything else MUST be ...

CVSS3: 7.3
1%
Низкий
больше 3 лет назад
redhat логотип
CVE-2022-31081

HTTP::Daemon is a simple http server class written in perl. Versions prior to 6.15 are subject to a vulnerability which could potentially be exploited to gain privileged access to APIs or poison intermediate caches. It is uncertain how large the risks are, most Perl based applications are served on top of Nginx or Apache, not on the `HTTP::Daemon`. This library is commonly used for local development and tests. Users are advised to update to resolve this issue. Users unable to upgrade may add additional request handling logic as a mitigation. After calling `my $rqst = $conn->get_request()` one could inspect the returned `HTTP::Request` object. Querying the 'Content-Length' (`my $cl = $rqst->header('Content-Length')`) will show any abnormalities that should be dealt with by a `400` response. Expected strings of 'Content-Length' SHOULD consist of either a single non-negative integer, or, a comma separated repetition of that number. (that is `42` or `42, 42, 42`). Anything else MUST be ...

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-31081

HTTP::Daemon is a simple http server class written in perl. Versions prior to 6.15 are subject to a vulnerability which could potentially be exploited to gain privileged access to APIs or poison intermediate caches. It is uncertain how large the risks are, most Perl based applications are served on top of Nginx or Apache, not on the `HTTP::Daemon`. This library is commonly used for local development and tests. Users are advised to update to resolve this issue. Users unable to upgrade may add additional request handling logic as a mitigation. After calling `my $rqst = $conn->get_request()` one could inspect the returned `HTTP::Request` object. Querying the 'Content-Length' (`my $cl = $rqst->header('Content-Length')`) will show any abnormalities that should be dealt with by a `400` response. Expected strings of 'Content-Length' SHOULD consist of either a single non-negative integer, or, a comma separated repetition of that number. (that is `42` or `42, 42, 42`). Anything else MUST be rej

CVSS3: 7.3
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-31081

HTTP::Daemon is a simple http server class written in perl. Versions p ...

CVSS3: 7.3
1%
Низкий
больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:2874-1

Security update for perl-HTTP-Daemon

1%
Низкий
больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:2872-1

Security update for perl-HTTP-Daemon

1%
Низкий
больше 3 лет назад
fstec логотип
BDU:2022-05817

Уязвимость демона HTTP-сервера HTTP Daemon, связанная с непоследовательной интерпритацией HTTP-запросов, позволяющая нарушителю повысить свои привилегии

CVSS3: 7.3
1%
Низкий
больше 3 лет назад
redos логотип
ROS-20240816-03

Уязвимость perl-HTTP-Daemon

CVSS3: 7.3
1%
Низкий
больше 1 года назад

Уязвимостей на страницу