HTTP Request Smuggling has been fixed in the Python WSGI HTTP Server Gunicorn. For Debian 11 bullseye, this problem has been fixed in version 20.1.0-1+deb11u1. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3996-1
Gunicorn, an event-based HTTP/WSGI server, fails to properly validate Transfer- Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security restrictions and access restricted endpoints. This issue is due . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3851-1
It was discovered that gunicorn, an event-based HTTP/WSGI server was susceptible to HTTP Response splitting. For the oldstable distribution (jessie), this problem has been fixed . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4186-1
It was discovered that there was an issue in the gunicorn HTTP server for Python applicatons where CRLF sequences could result in an attacker tricking the server into returning arbitrary headers. . Package : gunicorn Version : 0.14.5-3+deb7u2 CVE ID : CVE-2018-1000164 Debian Bug : #896548 It was discovered that there was an issue in the gunicorn HTTP server for Python applicatons where CRLF sequences could result in an attacker tricking the server into returning arbitrary headers. For more information and background, please see: For Debian 7 "Wheezy", this issue has been fixed in gunicorn version 0.14.5-3+deb7u2. We recommend that you upgrade your gunicorn packages. Regards, - -- ,'`. : :' : Chris Lamb `. `'`
Get the latest Linux and open source security news straight to your inbox.