← Back

CVE-2021-39185

nvd nist
Published: Sep 1, 2021Modified: Nov 21, 2024

JSON object

Loading...
9.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability: 3.9 / Impact: 5.2
Source: security-advisories@github.com (Secondary)

Description

Http4s is a minimal, idiomatic Scala interface for HTTP services. In http4s versions 0.21.26 and prior, 0.22.0 through 0.22.2, 0.23.0, 0.23.1, and 1.0.0-M1 through 1.0.0-M24, the default CORS configuration is vulnerable to an origin reflection attack. The middleware is also susceptible to a Null Origin Attack. The problem is fixed in 0.21.27, 0.22.3, 0.23.2, and 1.0.0-M25. The original `CORS` implementation and `CORSConfig` are deprecated. See the GitHub GHSA for more information, including code examples and workarounds.

Affected (28)

Products: Typelevel: Http4s
1 product
Http4s
Configuration A
28 vulnerable
Vulnerable SoftwareAffected Versions
Typelevel
Up to 0.21.26
From 0.22.0 to 0.22.2
Version 0.23.0
Version 0.23.1
Version 1.0.0 milestone10
Version 1.0.0 milestone11
Version 1.0.0 milestone12
Version 1.0.0 milestone13
Version 1.0.0 milestone14
Version 1.0.0 milestone15
Version 1.0.0 milestone16
Version 1.0.0 milestone17
Version 1.0.0 milestone18
Version 1.0.0 milestone19
Version 1.0.0 milestone1
Version 1.0.0 milestone20
Version 1.0.0 milestone21
Version 1.0.0 milestone22
Version 1.0.0 milestone23
Version 1.0.0 milestone24
Version 1.0.0 milestone2
Version 1.0.0 milestone3
Version 1.0.0 milestone4
Version 1.0.0 milestone5
Version 1.0.0 milestone6
Version 1.0.0 milestone7
Version 1.0.0 milestone8
Version 1.0.0 milestone9

References (4)

Source: security-advisories@github.com
Third Party Advisory
Source: security-advisories@github.com
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.