CVE-2021-38512: High severity actix Actix-http Rust vulnerability
Published Aug 10, 2021
·Updated
An issue was discovered in the actix-http crate before 3.0.0-beta.9 for Rust. HTTP/1 request smuggling (aka HRS) can occur, potentially leading to credential disclosure.
Affected Software
11 affected components
actix Actix-http Rust<3.0.0
actix Actix-http Rust=3.0.0
actix Actix-http Rust=3.0.0-beta1
actix Actix-http Rust=3.0.0-beta2
actix Actix-http Rust=3.0.0-beta3
actix Actix-http Rust=3.0.0-beta4
actix Actix-http Rust=3.0.0-beta5
actix Actix-http Rust=3.0.0-beta6
actix Actix-http Rust=3.0.0-beta7
actix Actix-http Rust=3.0.0-beta8
Fedoraproject Fedora=34
Event History
Aug 10, 2021
CVE Published
via MITRE·10:12 PM
Data Sourced
via MITRE·10:12 PM
Description
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What does CVE-2021-38512 refer to?
CVE-2021-38512 refers to a vulnerability in the actix-http crate that can lead to HTTP/1 request smuggling, potentially allowing credential disclosure.
2
What is the severity of CVE-2021-38512?
The severity level of CVE-2021-38512 is considered high due to the risk of credential disclosure.
3
How do I fix CVE-2021-38512?
To fix CVE-2021-38512, update the actix-http crate to version 3.0.0 or later.
4
Which versions are affected by CVE-2021-38512?
CVE-2021-38512 affects versions of the actix-http crate prior to 3.0.0-beta.9.
5
What potential impact does CVE-2021-38512 have?
The potential impact of CVE-2021-38512 includes unauthorized access to sensitive information through credential disclosure.