Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 6

Количество 6

ubuntu логотип

CVE-2022-41721

больше 3 лет назад

A request smuggling attack is possible when using MaxBytesHandler. When using MaxBytesHandler, the body of an HTTP request is not fully consumed. When the server attempts to read HTTP2 frames from the connection, it will instead be reading the body of the HTTP request, which could be attacker-manipulated to represent arbitrary HTTP2 requests.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-41721

больше 3 лет назад

A request smuggling attack is possible when using MaxBytesHandler. When using MaxBytesHandler, the body of an HTTP request is not fully consumed. When the server attempts to read HTTP2 frames from the connection, it will instead be reading the body of the HTTP request, which could be attacker-manipulated to represent arbitrary HTTP2 requests.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2022-41721

больше 3 лет назад

A request smuggling attack is possible when using MaxBytesHandler. When using MaxBytesHandler, the body of an HTTP request is not fully consumed. When the server attempts to read HTTP2 frames from the connection, it will instead be reading the body of the HTTP request, which could be attacker-manipulated to represent arbitrary HTTP2 requests.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2022-41721

больше 3 лет назад

Request smuggling due to improper request handling in golang.org/x/net/http2/h2c

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2022-41721

больше 3 лет назад

A request smuggling attack is possible when using MaxBytesHandler. Whe ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-fxg5-wq6x-vr4w

больше 3 лет назад

golang.org/x/net/http2/h2c vulnerable to request smuggling attack

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-41721

A request smuggling attack is possible when using MaxBytesHandler. When using MaxBytesHandler, the body of an HTTP request is not fully consumed. When the server attempts to read HTTP2 frames from the connection, it will instead be reading the body of the HTTP request, which could be attacker-manipulated to represent arbitrary HTTP2 requests.

CVSS3: 7.5
2%
Низкий
больше 3 лет назад
redhat логотип
CVE-2022-41721

A request smuggling attack is possible when using MaxBytesHandler. When using MaxBytesHandler, the body of an HTTP request is not fully consumed. When the server attempts to read HTTP2 frames from the connection, it will instead be reading the body of the HTTP request, which could be attacker-manipulated to represent arbitrary HTTP2 requests.

CVSS3: 7.5
2%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-41721

A request smuggling attack is possible when using MaxBytesHandler. When using MaxBytesHandler, the body of an HTTP request is not fully consumed. When the server attempts to read HTTP2 frames from the connection, it will instead be reading the body of the HTTP request, which could be attacker-manipulated to represent arbitrary HTTP2 requests.

CVSS3: 7.5
2%
Низкий
больше 3 лет назад
msrc логотип
CVE-2022-41721

Request smuggling due to improper request handling in golang.org/x/net/http2/h2c

CVSS3: 7.5
2%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-41721

A request smuggling attack is possible when using MaxBytesHandler. Whe ...

CVSS3: 7.5
2%
Низкий
больше 3 лет назад
github логотип
GHSA-fxg5-wq6x-vr4w

golang.org/x/net/http2/h2c vulnerable to request smuggling attack

CVSS3: 7.5
2%
Низкий
больше 3 лет назад

Уязвимостей на страницу