7.5

CVE-2023-22465

Exploit
Http4s is a Scala interface for HTTP services. Starting with version 0.1.0 and prior to versions 0.21.34, 0.22.15, 0.23.17, and 1.0.0-M38, the `User-Agent` and `Server` header parsers are susceptible to a fatal error on certain inputs.  In http4s, modeled headers are lazily parsed, so this only applies to services that explicitly request these typed headers. Fixes are released in 0.21.34, 0.22.15, 0.23.17, and 1.0.0-M38. As a workaround, use the weakly typed header interface.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
TypelevelHttp4s Version >= 0.1.0 < 0.21.34
TypelevelHttp4s Version >= 0.22.0 < 0.22.15
TypelevelHttp4s Version >= 0.23.0 < 0.23.17
TypelevelHttp4s Version1.0.0 Updatemilestone1
TypelevelHttp4s Version1.0.0 Updatemilestone10
TypelevelHttp4s Version1.0.0 Updatemilestone11
TypelevelHttp4s Version1.0.0 Updatemilestone12
TypelevelHttp4s Version1.0.0 Updatemilestone13
TypelevelHttp4s Version1.0.0 Updatemilestone14
TypelevelHttp4s Version1.0.0 Updatemilestone15
TypelevelHttp4s Version1.0.0 Updatemilestone16
TypelevelHttp4s Version1.0.0 Updatemilestone17
TypelevelHttp4s Version1.0.0 Updatemilestone18
TypelevelHttp4s Version1.0.0 Updatemilestone19
TypelevelHttp4s Version1.0.0 Updatemilestone2
TypelevelHttp4s Version1.0.0 Updatemilestone20
TypelevelHttp4s Version1.0.0 Updatemilestone21
TypelevelHttp4s Version1.0.0 Updatemilestone22
TypelevelHttp4s Version1.0.0 Updatemilestone23
TypelevelHttp4s Version1.0.0 Updatemilestone24
TypelevelHttp4s Version1.0.0 Updatemilestone25
TypelevelHttp4s Version1.0.0 Updatemilestone26
TypelevelHttp4s Version1.0.0 Updatemilestone27
TypelevelHttp4s Version1.0.0 Updatemilestone28
TypelevelHttp4s Version1.0.0 Updatemilestone29
TypelevelHttp4s Version1.0.0 Updatemilestone3
TypelevelHttp4s Version1.0.0 Updatemilestone30
TypelevelHttp4s Version1.0.0 Updatemilestone31
TypelevelHttp4s Version1.0.0 Updatemilestone32
TypelevelHttp4s Version1.0.0 Updatemilestone33
TypelevelHttp4s Version1.0.0 Updatemilestone34
TypelevelHttp4s Version1.0.0 Updatemilestone35
TypelevelHttp4s Version1.0.0 Updatemilestone36
TypelevelHttp4s Version1.0.0 Updatemilestone37
TypelevelHttp4s Version1.0.0 Updatemilestone4
TypelevelHttp4s Version1.0.0 Updatemilestone5
TypelevelHttp4s Version1.0.0 Updatemilestone6
TypelevelHttp4s Version1.0.0 Updatemilestone7
TypelevelHttp4s Version1.0.0 Updatemilestone8
TypelevelHttp4s Version1.0.0 Updatemilestone9
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.07% 0.212
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
security-advisories@github.com 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.