PT-2019-20153 · Waitress · Waitress

Publicado

2019-12-20

·

Atualizado

2019-12-20

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
Name of the Vulnerable Software and Affected Versions Waitress versions 1.3.1 and earlier
Description The issue arises from the implementation of a part of the RFC7230 in Waitress, where it recognizes a single LF as a line terminator and ignores any preceding CR. This can cause a discrepancy in how the front-end and back-end servers parse HTTP messages, potentially leading to HTTP request smuggling or splitting. This discrepancy occurs when the front-end server does not parse header fields with an LF in the same way as it does those with a CRLF.
Recommendations For Waitress versions 1.3.1 and earlier, update to version 1.4.0 to resolve the issue.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

PYSEC-2019-66

Produtos afetados

Waitress