CVE-2022-24775
Improper Input Validation in guzzlehttp/psr7
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
guzzlehttp/psr7 is a PSR-7 HTTP message library. Versions prior to 1.8.4 and 2.1.1 are vulnerable to improper header parsing. An attacker could sneak in a new line character and pass untrusted values. The issue is patched in 1.8.4 and 2.1.1. There are currently no known workarounds.
guzzlehttp/psr7 es una biblioteca de mensajes HTTP PSR-7. Las versiones anteriores a 1.8.4 y 2.1.1 son vulnerables a un análisis inapropiado de los encabezados. Un atacante podría colar un carácter de nueva línea y pasar valores no confiables. El problema está parcheado en versiones 1.8.4 y 2.1.1. Actualmente no se presentan medidas de mitigación conocidas
guzzlehttp/psr7 is a PSR-7 HTTP message library. Versions prior to 1.8.4 and 2.1.1 are vulnerable to improper header parsing. An attacker could sneak in a new line character and pass untrusted values. The issue is patched in 1.8.4 and 2.1.1. There are currently no known workarounds. Some WordPress plugins and themes use this dependency though that doesn’t necessarily mean the plugin itself is vulnerable to exploitation.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-02-10 CVE Reserved
- 2022-03-21 CVE Published
- 2024-08-03 CVE Updated
- 2024-10-25 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://github.com/guzzle/psr7/security/advisories/GHSA-q7rv-6hp3-vh96 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | >= 8.0.0 < 9.2.16 Search vendor "Drupal" for product "Drupal" and version " >= 8.0.0 < 9.2.16" | - |
Affected
| ||||||
Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | >= 9.3.0 < 9.3.9 Search vendor "Drupal" for product "Drupal" and version " >= 9.3.0 < 9.3.9" | - |
Affected
| ||||||
Guzzlephp Search vendor "Guzzlephp" | Psr-7 Search vendor "Guzzlephp" for product "Psr-7" | < 1.8.4 Search vendor "Guzzlephp" for product "Psr-7" and version " < 1.8.4" | - |
Affected
| ||||||
Guzzlephp Search vendor "Guzzlephp" | Psr-7 Search vendor "Guzzlephp" for product "Psr-7" | >= 2.0.0 < 2.1.1 Search vendor "Guzzlephp" for product "Psr-7" and version " >= 2.0.0 < 2.1.1" | - |
Affected
|