Bug 2250179 (CVE-2023-47641)
| Summary: | CVE-2023-47641 python-aiohttp: inconsistent interpretation of `Content-Length` vs. `Transfer-Encoding` | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Robb Gatica <rgatica> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | low | Docs Contact: | |
| Priority: | low | ||
| Version: | unspecified | CC: | adudiak, bbuckingham, bcourt, brking, caswilli, dfreiber, drow, ehelms, epacific, ggainey, gsuckevi, gtanzill, haoli, hkataria, jburrell, jcammara, jhardy, jmitchel, jneedle, jobarker, jsherril, jtanner, juwatts, jwong, kaycoth, kshier, luizcosta, lzap, mabashia, mhulan, mminar, nmoumoul, nweather, orabin, pbraun, pcreech, rbiba, rbobbitt, rchan, simaishi, smcdonal, sskracic, stcannon, sthirugn, teagle, tfister, thavo, tsasak, vkrizan, vkumar, vmugicag, yguenane, zsadeh |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | aiohttp 3.8.0 | Doc Type: | If docs needed, set a value |
| Doc Text: |
Aiohttp is susceptible to an HTTP request smuggling vulnerability due to inadequate parsing of the HTTP Content-Length (CL) and Transfer-Encoding (TE) headers. This flaw allows an attacker to bypass proxy rules, poisoning sockets to other users, such as passing Authentication Headers. Additionally, if an open redirect is present, the attacker can leverage it to redirect random users to their website and log the requests.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2250180 | ||
| Bug Blocks: | 2250178 | ||
|
Description
Robb Gatica
2023-11-16 20:30:47 UTC
griffon --profile triage service products-contain-component aiohttp ansible_automation_platform-2 python-aiohttp ansible_automation_platform-2 python3x-aiohttp rhn_satellite_6 python-aiohttp rhn_satellite_6 python-aiohttp-socks rhn_satellite_6 python-aiohttp-xmlrpc rhn_satellite_6 tfm-pulpcore-python-aiohttp rhn_satellite_6 tfm-pulpcore-python-aiohttp-xmlrpc rhui-4 python-aiohttp rhui-4 python-aiohttp-xmlrpc |