Publish GHSA-q2qj-628g-vhfw

This commit is contained in:
advisory-database[bot]
2023-05-22 14:39:46 +00:00
parent f4f9c69506
commit f122609ad2
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q2qj-628g-vhfw",
"modified": "2023-04-18T22:20:42Z",
"modified": "2023-05-22T14:38:30Z",
"published": "2023-04-18T22:20:42Z",
"aliases": [
"CVE-2023-30536"
],
"summary": "Insecure header validation in slim/psr7",
"details": "### Impact\n\nAn attacker could sneak in a newline (`\\n`) into both the header names and values. While the specification states that `\\r\\n\\r\\n` is used to terminate the header list, many servers in the wild will also accept `\\n\\n`. An attacker that is able to control the header names that are passed to Slilm-Psr7 would be able to intentionally craft invalid messages, possibly causing application errors or invalid HTTP requests being sent out with an PSR-18 HTTP client. The latter might present a denial of service vector if a remote services web application firewall bans the application due to the receipt of malformed requests.\n\n### Patches\n\nThe issue is patched in 1.6.1\n\n### Workarounds\n\nIn Slim-Psr7 1.6.0 and below, validate HTTP header keys and/or values, and if using user-supplied values, filter them to strip off leading or trailing newline characters before calling withHeader().\n\n### Acknowledgments\n\nWe are very grateful to and thank <a href=\"https://gjcampbell.co.uk/\">Graham Campbell</a> for reporting and working with us on this issue.\n\n### References\n\n* Guzzle: CVE-2023-29197, with advisory GHSA-wxmh-65f7-jcvw\n* Laminas Diactoros: CVE-2023-29530, with advisory GHSA-xv3h-4844-9h36\n* https://www.rfc-editor.org/rfc/rfc7230#section-3.2.4",
"details": "### Impact\n\nAn attacker could sneak in a newline (`\\n`) into both the header names and values. While the specification states that `\\r\\n\\r\\n` is used to terminate the header list, many servers in the wild will also accept `\\n\\n`. An attacker that is able to control the header names that are passed to Slilm-Psr7 would be able to intentionally craft invalid messages, possibly causing application errors or invalid HTTP requests being sent out with an PSR-18 HTTP client. The latter might present a denial of service vector if a remote services web application firewall bans the application due to the receipt of malformed requests.\n\n### Patches\n\nThe issue is patched in 1.6.1, 1.5.1, and 1.4.1.\n\n### Workarounds\n\nIn Slim-Psr7 prior to 1.6.1, 1.5.1, and 1.4.1, validate HTTP header keys and/or values, and if using user-supplied values, filter them to strip off leading or trailing newline characters before calling withHeader().\n\n### Acknowledgments\n\nWe are very grateful to and thank <a href=\"https://gjcampbell.co.uk/\">Graham Campbell</a> for reporting and working with us on this issue.\n\n### References\n\n* Guzzle: CVE-2023-29197, with advisory GHSA-wxmh-65f7-jcvw\n* Laminas Diactoros: CVE-2023-29530, with advisory GHSA-xv3h-4844-9h36\n* https://www.rfc-editor.org/rfc/rfc7230#section-3.2.4",
"severity": [
{
"type": "CVSS_V3",
@@ -25,7 +25,7 @@
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
"introduced": "1.6"
},
{
"fixed": "1.6.1"
@@ -33,6 +33,44 @@
]
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "slim/psr7"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "1.5"
},
{
"fixed": "1.5.1"
}
]
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "slim/psr7"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "1.4.1"
}
]
}
]
}
],
"references": [
@@ -44,6 +82,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30536"
},
{
"type": "WEB",
"url": "https://github.com/slimphp/Slim-Psr7/issues/284#issuecomment-1541328898"
},
{
"type": "WEB",
"url": "https://github.com/slimphp/Slim-Psr7/commit/ed1d553225dd190875d8814c47460daed4b550bb"
@@ -52,6 +94,18 @@
"type": "PACKAGE",
"url": "https://github.com/slimphp/Slim-Psr7"
},
{
"type": "WEB",
"url": "https://github.com/slimphp/Slim-Psr7/releases/tag/1.4.1"
},
{
"type": "WEB",
"url": "https://github.com/slimphp/Slim-Psr7/releases/tag/1.5.1"
},
{
"type": "WEB",
"url": "https://github.com/slimphp/Slim-Psr7/releases/tag/1.6.1"
},
{
"type": "WEB",
"url": "https://www.rfc-editor.org/rfc/rfc7230#section-3.2.4"