← Back

CVE-2023-22465

nvd nist
Published: Jan 4, 2023Modified: Nov 21, 2024

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

Http4s is a Scala interface for HTTP services. Starting with version 0.1.0 and prior to versions 0.21.34, 0.22.15, 0.23.17, and 1.0.0-M38, the `User-Agent` and `Server` header parsers are susceptible to a fatal error on certain inputs. In http4s, modeled headers are lazily parsed, so this only applies to services that explicitly request these typed headers. Fixes are released in 0.21.34, 0.22.15, 0.23.17, and 1.0.0-M38. As a workaround, use the weakly typed header interface.

Affected (40)

Products: Typelevel: Http4s
1 product
Http4s
Configuration A
40 vulnerable
Vulnerable SoftwareAffected Versions
Typelevel
From 0.1.0 to 0.21.34
From 0.22.0 to 0.22.15
From 0.23.0 to 0.23.17
Version 1.0.0 milestone10
Version 1.0.0 milestone11
Version 1.0.0 milestone12
Version 1.0.0 milestone13
Version 1.0.0 milestone14
Version 1.0.0 milestone15
Version 1.0.0 milestone16
Version 1.0.0 milestone17
Version 1.0.0 milestone18
Version 1.0.0 milestone19
Version 1.0.0 milestone1
Version 1.0.0 milestone20
Version 1.0.0 milestone21
Version 1.0.0 milestone22
Version 1.0.0 milestone23
Version 1.0.0 milestone24
Version 1.0.0 milestone25
Version 1.0.0 milestone26
Version 1.0.0 milestone27
Version 1.0.0 milestone28
Version 1.0.0 milestone29
Version 1.0.0 milestone2
Version 1.0.0 milestone30
Version 1.0.0 milestone31
Version 1.0.0 milestone32
Version 1.0.0 milestone33
Version 1.0.0 milestone34
Version 1.0.0 milestone35
Version 1.0.0 milestone36
Version 1.0.0 milestone37
Version 1.0.0 milestone3
Version 1.0.0 milestone4
Version 1.0.0 milestone5
Version 1.0.0 milestone6
Version 1.0.0 milestone7
Version 1.0.0 milestone8
Version 1.0.0 milestone9

References (2)

Source: security-advisories@github.com
ExploitMitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMitigationThird Party Advisory

Timeline

No history available yet.