You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Path to dependency file: /encryption-on-the-fly/requirements.txt
Path to vulnerable library: /teSource-ArchiveExtractor_747dfafb-5007-43bc-af58-18b19f548702/20190702203809_87843/20190702203750_depth_0/gunicorn-19.9.0-py2.py3-none-any/gunicorn
Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security restrictions and access restricted endpoints. This issue is due to Gunicorn's handling of Transfer-Encoding headers, where it incorrectly processes requests with multiple, conflicting Transfer-Encoding headers, treating them as chunked regardless of the final encoding specified. This vulnerability allows for a range of attacks including cache poisoning, session manipulation, and data exposure.
CVE-2024-1135 - High Severity Vulnerability
Vulnerable Library - gunicorn-19.9.0-py2.py3-none-any.whl
WSGI HTTP Server for UNIX
Library home page: https://files.pythonhosted.org/packages/8c/da/b8dd8deb741bff556db53902d4706774c8e1e67265f69528c14c003644e6/gunicorn-19.9.0-py2.py3-none-any.whl
Path to dependency file: /encryption-on-the-fly/requirements.txt
Path to vulnerable library: /teSource-ArchiveExtractor_747dfafb-5007-43bc-af58-18b19f548702/20190702203809_87843/20190702203750_depth_0/gunicorn-19.9.0-py2.py3-none-any/gunicorn
Dependency Hierarchy:
Found in base branch: master
Vulnerability Details
Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security restrictions and access restricted endpoints. This issue is due to Gunicorn's handling of Transfer-Encoding headers, where it incorrectly processes requests with multiple, conflicting Transfer-Encoding headers, treating them as chunked regardless of the final encoding specified. This vulnerability allows for a range of attacks including cache poisoning, session manipulation, and data exposure.
Publish Date: 2024-04-16
URL: CVE-2024-1135
CVSS 3 Score Details (7.4)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Release Date: 2024-04-16
Fix Resolution: gunicorn - 22.0.0
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: