CVE-2020-36202: XSS
Published Jan 22, 2021
·Updated
An issue was discovered in the async-h1 crate before 2.3.0 for Rust. Request smuggling can occur when used behind a reverse proxy.
Affected Software
1 affected component
rust-lang Async-h1 Rust<2.3.0
Remediation
Patch Available
Event History
Jan 22, 2021
CVE Published
via MITRE·09:07 AM
Data Sourced
via MITRE·09:07 AM
Description
Frequently Asked Questions
1
What is CVE-2020-36202?
CVE-2020-36202 is a vulnerability in the async-h1 crate before version 2.3.0 for Rust that allows for request smuggling when used behind a reverse proxy.
2
What is the severity of CVE-2020-36202?
CVE-2020-36202 has a severity rating of 6.1 (Medium).
3
Which software is affected by CVE-2020-36202?
The async-h1 crate before version 2.3.0 for Rust is affected by CVE-2020-36202.
4
How can request smuggling occur with CVE-2020-36202?
Request smuggling can occur when using the async-h1 crate before version 2.3.0 for Rust behind a reverse proxy.
5
Where can I find more information about CVE-2020-36202?
More information about CVE-2020-36202 can be found at https://rustsec.org/advisories/RUSTSEC-2020-0093.html.