Skip to content

Commit

Permalink
Merge pull request #355 from snoopysecurity/add-tiny-http-request-smu…
Browse files Browse the repository at this point in the history
…ggling

Add tiny-http Request Smuggling
  • Loading branch information
Shnatsel committed Aug 21, 2020
2 parents 4b1e065 + 1400f85 commit 50e585f
Showing 1 changed file with 19 additions and 0 deletions.
19 changes: 19 additions & 0 deletions crates/tiny_http/RUSTSEC-2020-0000.toml
@@ -0,0 +1,19 @@
[advisory]
id = "RUSTSEC-2020-0000"
package = "tiny_http"
date = "2020-06-16"
title = "HTTP Request smuggling through malformed Transfer Encoding headers"
url = "https://github.com/tiny-http/tiny-http/issues/173"
keywords = ["http", "request-smuggling"]
description = """
HTTP pipelining issues and request smuggling attacks are possible due to incorrect
Transfer encoding header parsing.
It is possible conduct HTTP request smuggling attacks (CL:TE/TE:TE) by sending invalid Transfer Encoding headers.
By manipulating the HTTP response the attacker could poison a web-cache, perform an XSS attack, or obtain sensitive information
from requests other than their own.
"""

[versions]
patched = []

0 comments on commit 50e585f

Please sign in to comment.