PT-2022-5090 · Pallets+1 · Werkzeug+1
Acipmo
·
Published
2022-02-17
·
Updated
2025-04-11
·
CVE-2022-29361
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Pallets Werkzeug versions 2.1.0 and below
Description
The issue is related to improper parsing of HTTP requests, which can allow an attacker to perform HTTP Request Smuggling using a crafted HTTP request with multiple requests included inside the body. This can occur in unsupported configurations involving development mode and an HTTP server from outside the Werkzeug project. The vendor's position is that this behavior is only possible under specific conditions.
Recommendations
For versions 2.1.0 and below, consider disabling development mode and using an HTTP server within the Werkzeug project to minimize the risk of exploitation. Restrict access to the HTTP request parsing functionality until a patch is available. Avoid using crafted HTTP requests with multiple requests included inside the body in the affected API endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
HTTP Request/Response Smuggling
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Werkzeug