PT-2020-13290 · Alvaro Lopez Ortega · Cherokee
Pjlantz
·
Published
2020-07-27
·
Updated
2022-11-29
·
CVE-2020-12845
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Cherokee versions 0.4.27 through 1.2.104
Description
The issue is a denial of service caused by NULL pointer dereferences. A remote unauthenticated attacker can crash the server by sending an HTTP request to protected resources using a malformed
Authorization header. This header is mishandled during a cherokee buffer add call within cherokee validator parse basic or cherokee validator parse digest functions.Recommendations
For Cherokee versions 0.4.27 through 1.2.104, as a temporary workaround, consider restricting access to protected resources to minimize the risk of exploitation. Avoid using malformed
Authorization headers in HTTP requests until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
DoS
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cherokee