** DISPUTED ** Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perform HTTP Request Smuggling using a crafted HTTP request with multiple requests included inside the body. NOTE: the vendor's position is that this behavior can only occur in unsupported configurations involving development mode and an HTTP server from outside the Werkzeug project.
References
Link | Resource |
---|---|
https://github.com/pallets/werkzeug/commit/9a3a981d70d2e9ec3344b5192f86fcaf3210cd85 | Patch Third Party Advisory |
https://github.com/pallets/werkzeug/issues/2420 | Issue Tracking Third Party Advisory |
Configurations
Information
Published : 2022-05-24 18:15
Updated : 2022-06-07 14:01
NVD link : CVE-2022-29361
Mitre link : CVE-2022-29361
JSON object : View
CWE
CWE-444
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
Products Affected
palletsprojects
- werkzeug