ZeroHour

CVE-2018-1000164

PoC ×2
CVSS 3.0
7.5 high
EPSS
2%p83
Published
()
Modified
Description

gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers vulnerability in "process_headers" function in "gunicorn/http/wsgi.py" that can result in an attacker causing the server to return arbitrary HTTP headers. This vulnerability appears to have been fixed in 19.5.0.

Vendors
gunicorndebian
Products
gunicorn, debian linux
Ecosystems
pip
Weakness
CWE-93
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
GHSA
GHSA-32pc-xphx-q4f6 (high)

In the news

No ingested article mentions this CVE yet.