CVE-2020-7655

netius prior to 1.17.58 is vulnerable to HTTP Request Smuggling. HTTP pipelining issues and request smuggling attacks might be possible due to incorrect Transfer encoding header parsing which could allow for CL:TE or TE:TE attacks.
References
Link Resource
https://snyk.io/vuln/SNYK-PYTHON-NETIUS-569141 Patch Third Party Advisory
https://snyk.io/vuln/SNYK-PYTHON-NETIUS-569141 Patch Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:hive:netius:*:*:*:*:*:*:*:*

History

21 Nov 2024, 05:37

Type Values Removed Values Added
References () https://snyk.io/vuln/SNYK-PYTHON-NETIUS-569141 - Patch, Third Party Advisory () https://snyk.io/vuln/SNYK-PYTHON-NETIUS-569141 - Patch, Third Party Advisory

Information

Published : 2020-05-21 15:15

Updated : 2024-11-21 05:37


NVD link : CVE-2020-7655

Mitre link : CVE-2020-7655

CVE.ORG link : CVE-2020-7655


JSON object : View

Products Affected

hive

  • netius
CWE
CWE-444

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')