Files
advisory-db/crates/tiny_http/RUSTSEC-2020-0031.toml
github-actions[bot] c12999b9c8 Assigned RUSTSEC-2020-0031 to tiny_http (#358)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2020-08-21 17:59:34 -04:00

20 lines
701 B
TOML

[advisory]
id = "RUSTSEC-2020-0031"
package = "tiny_http"
date = "2020-06-16"
title = "HTTP Request smuggling through malformed Transfer Encoding headers"
url = "https://github.com/tiny-http/tiny-http/issues/173"
keywords = ["http", "request-smuggling"]
description = """
HTTP pipelining issues and request smuggling attacks are possible due to incorrect
Transfer encoding header parsing.
It is possible conduct HTTP request smuggling attacks (CL:TE/TE:TE) by sending invalid Transfer Encoding headers.
By manipulating the HTTP response the attacker could poison a web-cache, perform an XSS attack, or obtain sensitive information
from requests other than their own.
"""
[versions]
patched = []