diff --git a/advisories/github-reviewed/2023/04/GHSA-q2qj-628g-vhfw/GHSA-q2qj-628g-vhfw.json b/advisories/github-reviewed/2023/04/GHSA-q2qj-628g-vhfw/GHSA-q2qj-628g-vhfw.json index 803dd8865b7..ea373a7e681 100644 --- a/advisories/github-reviewed/2023/04/GHSA-q2qj-628g-vhfw/GHSA-q2qj-628g-vhfw.json +++ b/advisories/github-reviewed/2023/04/GHSA-q2qj-628g-vhfw/GHSA-q2qj-628g-vhfw.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-q2qj-628g-vhfw", - "modified": "2023-04-18T22:20:42Z", + "modified": "2023-05-22T14:38:30Z", "published": "2023-04-18T22:20:42Z", "aliases": [ "CVE-2023-30536" ], "summary": "Insecure header validation in slim/psr7", - "details": "### Impact\n\nAn attacker could sneak in a newline (`\\n`) into both the header names and values. While the specification states that `\\r\\n\\r\\n` is used to terminate the header list, many servers in the wild will also accept `\\n\\n`. An attacker that is able to control the header names that are passed to Slilm-Psr7 would be able to intentionally craft invalid messages, possibly causing application errors or invalid HTTP requests being sent out with an PSR-18 HTTP client. The latter might present a denial of service vector if a remote service’s web application firewall bans the application due to the receipt of malformed requests.\n\n### Patches\n\nThe issue is patched in 1.6.1\n\n### Workarounds\n\nIn Slim-Psr7 1.6.0 and below, validate HTTP header keys and/or values, and if using user-supplied values, filter them to strip off leading or trailing newline characters before calling withHeader().\n\n### Acknowledgments\n\nWe are very grateful to and thank Graham Campbell for reporting and working with us on this issue.\n\n### References\n\n* Guzzle: CVE-2023-29197, with advisory GHSA-wxmh-65f7-jcvw\n* Laminas Diactoros: CVE-2023-29530, with advisory GHSA-xv3h-4844-9h36\n* https://www.rfc-editor.org/rfc/rfc7230#section-3.2.4", + "details": "### Impact\n\nAn attacker could sneak in a newline (`\\n`) into both the header names and values. While the specification states that `\\r\\n\\r\\n` is used to terminate the header list, many servers in the wild will also accept `\\n\\n`. An attacker that is able to control the header names that are passed to Slilm-Psr7 would be able to intentionally craft invalid messages, possibly causing application errors or invalid HTTP requests being sent out with an PSR-18 HTTP client. The latter might present a denial of service vector if a remote service’s web application firewall bans the application due to the receipt of malformed requests.\n\n### Patches\n\nThe issue is patched in 1.6.1, 1.5.1, and 1.4.1.\n\n### Workarounds\n\nIn Slim-Psr7 prior to 1.6.1, 1.5.1, and 1.4.1, validate HTTP header keys and/or values, and if using user-supplied values, filter them to strip off leading or trailing newline characters before calling withHeader().\n\n### Acknowledgments\n\nWe are very grateful to and thank Graham Campbell for reporting and working with us on this issue.\n\n### References\n\n* Guzzle: CVE-2023-29197, with advisory GHSA-wxmh-65f7-jcvw\n* Laminas Diactoros: CVE-2023-29530, with advisory GHSA-xv3h-4844-9h36\n* https://www.rfc-editor.org/rfc/rfc7230#section-3.2.4", "severity": [ { "type": "CVSS_V3", @@ -25,7 +25,7 @@ "type": "ECOSYSTEM", "events": [ { - "introduced": "0" + "introduced": "1.6" }, { "fixed": "1.6.1" @@ -33,6 +33,44 @@ ] } ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "slim/psr7" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "1.5" + }, + { + "fixed": "1.5.1" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "slim/psr7" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.4.1" + } + ] + } + ] } ], "references": [ @@ -44,6 +82,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30536" }, + { + "type": "WEB", + "url": "https://github.com/slimphp/Slim-Psr7/issues/284#issuecomment-1541328898" + }, { "type": "WEB", "url": "https://github.com/slimphp/Slim-Psr7/commit/ed1d553225dd190875d8814c47460daed4b550bb" @@ -52,6 +94,18 @@ "type": "PACKAGE", "url": "https://github.com/slimphp/Slim-Psr7" }, + { + "type": "WEB", + "url": "https://github.com/slimphp/Slim-Psr7/releases/tag/1.4.1" + }, + { + "type": "WEB", + "url": "https://github.com/slimphp/Slim-Psr7/releases/tag/1.5.1" + }, + { + "type": "WEB", + "url": "https://github.com/slimphp/Slim-Psr7/releases/tag/1.6.1" + }, { "type": "WEB", "url": "https://www.rfc-editor.org/rfc/rfc7230#section-3.2.4"