Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Jamadden

#31848of 56,326
8.7Total CVSS
Vulnerabilities · 1
PT-2018-3488
8.7
2018-04-18
Gunicorn · Unicorn · CVE-2018-1000164
Name of the Vulnerable Software and Affected Versions: gunicorn versions prior to 19.5.0 Description: The issue is related to an improper neutralization of CRLF sequences in HTTP headers, which can be exploited to return arbitrary HTTP headers. This can potentially lead to cross-site scripting (XSS) attacks. The vulnerability is located in the `process headers` function in `gunicorn/http/wsgi.py`. Recommendations: For gunicorn versions prior to 19.5.0, update to version 19.5.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the `process headers` function in `gunicorn/http/wsgi.py` to minimize the risk of exploitation.