From f122609ad27cbd331257e7bfe878142a7071d463 Mon Sep 17 00:00:00 2001
From: "advisory-database[bot]"
<45398580+advisory-database[bot]@users.noreply.github.com>
Date: Mon, 22 May 2023 14:39:46 +0000
Subject: [PATCH] Publish GHSA-q2qj-628g-vhfw
---
.../GHSA-q2qj-628g-vhfw.json | 60 ++++++++++++++++++-
1 file changed, 57 insertions(+), 3 deletions(-)
diff --git a/advisories/github-reviewed/2023/04/GHSA-q2qj-628g-vhfw/GHSA-q2qj-628g-vhfw.json b/advisories/github-reviewed/2023/04/GHSA-q2qj-628g-vhfw/GHSA-q2qj-628g-vhfw.json
index 803dd8865b7..ea373a7e681 100644
--- a/advisories/github-reviewed/2023/04/GHSA-q2qj-628g-vhfw/GHSA-q2qj-628g-vhfw.json
+++ b/advisories/github-reviewed/2023/04/GHSA-q2qj-628g-vhfw/GHSA-q2qj-628g-vhfw.json
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q2qj-628g-vhfw",
- "modified": "2023-04-18T22:20:42Z",
+ "modified": "2023-05-22T14:38:30Z",
"published": "2023-04-18T22:20:42Z",
"aliases": [
"CVE-2023-30536"
],
"summary": "Insecure header validation in slim/psr7",
- "details": "### Impact\n\nAn attacker could sneak in a newline (`\\n`) into both the header names and values. While the specification states that `\\r\\n\\r\\n` is used to terminate the header list, many servers in the wild will also accept `\\n\\n`. An attacker that is able to control the header names that are passed to Slilm-Psr7 would be able to intentionally craft invalid messages, possibly causing application errors or invalid HTTP requests being sent out with an PSR-18 HTTP client. The latter might present a denial of service vector if a remote service’s web application firewall bans the application due to the receipt of malformed requests.\n\n### Patches\n\nThe issue is patched in 1.6.1\n\n### Workarounds\n\nIn Slim-Psr7 1.6.0 and below, validate HTTP header keys and/or values, and if using user-supplied values, filter them to strip off leading or trailing newline characters before calling withHeader().\n\n### Acknowledgments\n\nWe are very grateful to and thank Graham Campbell for reporting and working with us on this issue.\n\n### References\n\n* Guzzle: CVE-2023-29197, with advisory GHSA-wxmh-65f7-jcvw\n* Laminas Diactoros: CVE-2023-29530, with advisory GHSA-xv3h-4844-9h36\n* https://www.rfc-editor.org/rfc/rfc7230#section-3.2.4",
+ "details": "### Impact\n\nAn attacker could sneak in a newline (`\\n`) into both the header names and values. While the specification states that `\\r\\n\\r\\n` is used to terminate the header list, many servers in the wild will also accept `\\n\\n`. An attacker that is able to control the header names that are passed to Slilm-Psr7 would be able to intentionally craft invalid messages, possibly causing application errors or invalid HTTP requests being sent out with an PSR-18 HTTP client. The latter might present a denial of service vector if a remote service’s web application firewall bans the application due to the receipt of malformed requests.\n\n### Patches\n\nThe issue is patched in 1.6.1, 1.5.1, and 1.4.1.\n\n### Workarounds\n\nIn Slim-Psr7 prior to 1.6.1, 1.5.1, and 1.4.1, validate HTTP header keys and/or values, and if using user-supplied values, filter them to strip off leading or trailing newline characters before calling withHeader().\n\n### Acknowledgments\n\nWe are very grateful to and thank Graham Campbell for reporting and working with us on this issue.\n\n### References\n\n* Guzzle: CVE-2023-29197, with advisory GHSA-wxmh-65f7-jcvw\n* Laminas Diactoros: CVE-2023-29530, with advisory GHSA-xv3h-4844-9h36\n* https://www.rfc-editor.org/rfc/rfc7230#section-3.2.4",
"severity": [
{
"type": "CVSS_V3",
@@ -25,7 +25,7 @@
"type": "ECOSYSTEM",
"events": [
{
- "introduced": "0"
+ "introduced": "1.6"
},
{
"fixed": "1.6.1"
@@ -33,6 +33,44 @@
]
}
]
+ },
+ {
+ "package": {
+ "ecosystem": "Packagist",
+ "name": "slim/psr7"
+ },
+ "ranges": [
+ {
+ "type": "ECOSYSTEM",
+ "events": [
+ {
+ "introduced": "1.5"
+ },
+ {
+ "fixed": "1.5.1"
+ }
+ ]
+ }
+ ]
+ },
+ {
+ "package": {
+ "ecosystem": "Packagist",
+ "name": "slim/psr7"
+ },
+ "ranges": [
+ {
+ "type": "ECOSYSTEM",
+ "events": [
+ {
+ "introduced": "0"
+ },
+ {
+ "fixed": "1.4.1"
+ }
+ ]
+ }
+ ]
}
],
"references": [
@@ -44,6 +82,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30536"
},
+ {
+ "type": "WEB",
+ "url": "https://github.com/slimphp/Slim-Psr7/issues/284#issuecomment-1541328898"
+ },
{
"type": "WEB",
"url": "https://github.com/slimphp/Slim-Psr7/commit/ed1d553225dd190875d8814c47460daed4b550bb"
@@ -52,6 +94,18 @@
"type": "PACKAGE",
"url": "https://github.com/slimphp/Slim-Psr7"
},
+ {
+ "type": "WEB",
+ "url": "https://github.com/slimphp/Slim-Psr7/releases/tag/1.4.1"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/slimphp/Slim-Psr7/releases/tag/1.5.1"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/slimphp/Slim-Psr7/releases/tag/1.6.1"
+ },
{
"type": "WEB",
"url": "https://www.rfc-editor.org/rfc/rfc7230#section-3.2.4"