9.1

CVE-2021-39185

Http4s is a minimal, idiomatic Scala interface for HTTP services. In http4s versions 0.21.26 and prior, 0.22.0 through 0.22.2, 0.23.0, 0.23.1, and 1.0.0-M1 through 1.0.0-M24, the default CORS configuration is vulnerable to an origin reflection attack. The middleware is also susceptible to a Null Origin Attack. The problem is fixed in 0.21.27, 0.22.3, 0.23.2, and 1.0.0-M25. The original `CORS` implementation and `CORSConfig` are deprecated. See the GitHub GHSA for more information, including code examples and workarounds.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
TypelevelHttp4s Version <= 0.21.26
TypelevelHttp4s Version >= 0.22.0 <= 0.22.2
TypelevelHttp4s Version0.23.0
TypelevelHttp4s Version0.23.1
TypelevelHttp4s Version1.0.0 Updatemilestone1
TypelevelHttp4s Version1.0.0 Updatemilestone10
TypelevelHttp4s Version1.0.0 Updatemilestone11
TypelevelHttp4s Version1.0.0 Updatemilestone12
TypelevelHttp4s Version1.0.0 Updatemilestone13
TypelevelHttp4s Version1.0.0 Updatemilestone14
TypelevelHttp4s Version1.0.0 Updatemilestone15
TypelevelHttp4s Version1.0.0 Updatemilestone16
TypelevelHttp4s Version1.0.0 Updatemilestone17
TypelevelHttp4s Version1.0.0 Updatemilestone18
TypelevelHttp4s Version1.0.0 Updatemilestone19
TypelevelHttp4s Version1.0.0 Updatemilestone2
TypelevelHttp4s Version1.0.0 Updatemilestone20
TypelevelHttp4s Version1.0.0 Updatemilestone21
TypelevelHttp4s Version1.0.0 Updatemilestone22
TypelevelHttp4s Version1.0.0 Updatemilestone23
TypelevelHttp4s Version1.0.0 Updatemilestone24
TypelevelHttp4s Version1.0.0 Updatemilestone3
TypelevelHttp4s Version1.0.0 Updatemilestone4
TypelevelHttp4s Version1.0.0 Updatemilestone5
TypelevelHttp4s Version1.0.0 Updatemilestone6
TypelevelHttp4s Version1.0.0 Updatemilestone7
TypelevelHttp4s Version1.0.0 Updatemilestone8
TypelevelHttp4s Version1.0.0 Updatemilestone9
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.386
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.4 10 4.9
AV:N/AC:L/Au:N/C:P/I:P/A:N
security-advisories@github.com 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CWE-346 Origin Validation Error

The product does not properly verify that the source of data or communication is valid.