First published: Wed Feb 17 2021(Updated: )
This affects all versions before 10.1.14 and from 10.2.0 to 10.2.4 of package com.typesafe.akka:akka-http-core. It allows multiple Transfer-Encoding headers.
Credit: report@snyk.io
Affected Software | Affected Version | How to fix |
---|---|---|
<10.1.14 | ||
>=10.2.0<10.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-23339.
The package affected by this vulnerability is com.typesafe.akka:akka-http-core.
All versions before 10.1.14 and from 10.2.0 to 10.2.4 of the package com.typesafe.akka:akka-http-core are affected.
This vulnerability allows multiple Transfer-Encoding headers.
The severity of CVE-2021-23339 is medium with a severity value of 6.5.
To fix CVE-2021-23339, update to version 10.1.14 or higher if you are using a version before 10.1.14, or update to a version higher than 10.2.4 if you are using a version between 10.2.0 and 10.2.4.