CVE-2019-16789
waitress - security update
描述
In Waitress through version 1.4.0, if a proxy server is used in front of waitress, an invalid request may be sent by an attacker that bypasses the front-end and is parsed differently by waitress leading to a potential for HTTP request smuggling. Specially crafted requests containing special whitespace characters in the Transfer-Encoding header would get parsed by Waitress as being a chunked request, but a front-end server would use the Content-Length instead as the Transfer-Encoding header is considered invalid due to containing invalid characters. If a front-end server does HTTP pipelining to a backend Waitress server this could lead to HTTP request splitting which may lead to potential cache poisoning or unexpected information disclosure. This issue is fixed in Waitress 1.4.1 through more strict HTTP field validation.
如何修補 CVE-2019-16789
要修補 CVE-2019-16789,請將受影響套件升級到下列已修補版本。
- —升級至 1.4.1-1 或更新版本
- —升級至 0.8.9-2+deb8u1 或更新版本
- —升級至 1.4.2 或更新版本
- —升級至 11d9e138125ad46e951027184b13242a3c1de017 或更新版本
CVE-2019-16789 正在被利用嗎?
低 — EPSS 為 2.6%,目前沒有觀察到大規模利用活動。
受影響套件(4)
- from 0, < 1.4.1-1
- from 0, < 0.8.9-2+deb8u1
- from 0, < 1.4.2
- from 0, < 11d9e138125ad46e951027184b13242a3c1de017 | from 0, < 1.4.1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:H/SA:N |
| osv | CVSS 3.1 | HIGH7.1 | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:N |