CVE-2018-1000164
Ubuntu Security Notice USN-4022-1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers vulnerability in "process_headers" function in "gunicorn/http/wsgi.py" that can result in an attacker causing the server to return arbitrary HTTP headers. This vulnerability appears to have been fixed in 19.5.0.
gunicorn 19.4.5 contiene CWE-113: neutralización incorrecta de secuencias CRLF en cabeceras HTTP en la función "process_headers" en "gunicorn/http/wsgi.py" que puede resultar en que un atacante provoque que el servidor devuelva cabeceras HTTP arbitrarias. La vulnerabilidad parece haber sido solucionada en la versión 19.5.0.
It was discovered that gunicorn improperly handled certain input. An attacker could potentially use this issue execute a cross-site scripting attack.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-04-02 CVE Reserved
- 2018-04-18 CVE Published
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-93: Improper Neutralization of CRLF Sequences ('CRLF Injection')
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
https://lists.debian.org/debian-lts-announce/2018/04/msg00022.html | Mailing List |
|
URL | Date | SRC |
---|---|---|
https://epadillas.github.io/2018/04/02/http-header-splitting-in-gunicorn-19.4.5 | 2024-08-05 | |
https://github.com/benoitc/gunicorn/issues/1227 | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://usn.ubuntu.com/4022-1 | 2019-06-19 | |
https://www.debian.org/security/2018/dsa-4186 | 2019-06-19 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Gunicorn Search vendor "Gunicorn" | Gunicorn Search vendor "Gunicorn" for product "Gunicorn" | 19.4.5 Search vendor "Gunicorn" for product "Gunicorn" and version "19.4.5" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 7.0 Search vendor "Debian" for product "Debian Linux" and version "7.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 8.0 Search vendor "Debian" for product "Debian Linux" and version "8.0" | - |
Affected
|