CVE-2020-35863: Critical severity hyper h2 vulnerability
Published Dec 31, 2020
·Updated
An issue was discovered in the hyper crate before 0.12.34 for Rust. HTTP request smuggling can occur. Remote code execution can occur in certain situations with an HTTP server on the loopback interface.
Affected Software
1 affected component
hyper Hyper Rust<0.12.34
Remediation
Patch Available
Event History
Dec 31, 2020
CVE Published
via MITRE·08:29 AM
Data Sourced
via MITRE·08:29 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-35863?
CVE-2020-35863 is categorized as a moderate severity vulnerability.
2
How do I fix CVE-2020-35863?
To fix CVE-2020-35863, upgrade the hyper crate to version 0.12.34 or later.
3
What types of attacks are associated with CVE-2020-35863?
CVE-2020-35863 is associated with HTTP request smuggling and potential remote code execution.
4
Which versions of hyper are affected by CVE-2020-35863?
Versions of hyper before 0.12.34 are affected by CVE-2020-35863.
5
Is it possible to exploit CVE-2020-35863 remotely?
Yes, CVE-2020-35863 can be exploited remotely under certain conditions involving an HTTP server on the loopback interface.