Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
7.5
CVE-2020-7694
- EPSS 0.23%
- Published 27.07.2020 12:15:11
- Last modified 21.11.2024 05:37:37
This affects all versions of package uvicorn. The request logger provided by the package is vulnerable to ASNI escape sequence injection. Whenever any HTTP request is received, the default behaviour of uvicorn is to log its details to either the cons...
5.3
CVE-2020-7695
- EPSS 0.3%
- Published 27.07.2020 12:15:11
- Last modified 21.11.2024 05:37:37
Uvicorn before 0.11.7 is vulnerable to HTTP response splitting. CRLF sequences are not escaped in the value of HTTP headers. Attackers can exploit this to add arbitrary headers to HTTP responses, or even return an arbitrary response body, whenever cr...
1