CVE-2023-29197

MEDIUM5.3EPSS 4.8%

php-guzzlehttp-psr7 - security update

發布日:2023/4/19修改日:2026/3/9
也稱為:GHSA-wxmh-65f7-jcvwDEBIAN-CVE-2023-29197DLA-3705-1

描述

### Impact Improper header parsing. An attacker could sneak in a newline (`\n`) into both the header names and values. While the specification states that `\r\n\r\n` is used to terminate the header list, many servers in the wild will also accept `\n\n`. ### Patches The issue is patched in 1.9.1 and 2.4.5. ### Workarounds There are no known workarounds. ### References * https://www.rfc-editor.org/rfc/rfc7230#section-3.2.4

受影響套件(4)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

參考連結(11)