CVE-2021-23339: HTTP Request Smuggling
Published Feb 17, 2021
·Updated
This affects all versions before 10.1.14 and from 10.2.0 to 10.2.4 of package com.typesafe.akka:akka-http-core. It allows multiple Transfer-Encoding headers.
Affected Software
2 affected components
Lightbend Akka-http<10.1.14
Lightbend Akka-http>=10.2.0<10.2.4
Event History
Feb 17, 2021
CVE Published
via MITRE·07:55 AM
Data Sourced
via MITRE·07:55 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-23339.
2
What package is affected by this vulnerability?
The package affected by this vulnerability is com.typesafe.akka:akka-http-core.
3
What versions of the package are affected?
All versions before 10.1.14 and from 10.2.0 to 10.2.4 of the package com.typesafe.akka:akka-http-core are affected.
4
What does this vulnerability allow?
This vulnerability allows multiple Transfer-Encoding headers.
5
What is the severity of CVE-2021-23339?
The severity of CVE-2021-23339 is medium with a severity value of 6.5.
6
How can I fix CVE-2021-23339?
To fix CVE-2021-23339, update to version 10.1.14 or higher if you are using a version before 10.1.14, or update to a version higher than 10.2.4 if you are using a version between 10.2.0 and 10.2.4.