First published: Tue May 24 2022(Updated: )
** DISPUTED ** Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perform HTTP Request Smuggling using a crafted HTTP request with multiple requests included inside the body. NOTE: the vendor's position is that this behavior can only occur in unsupported configurations involving development mode and an HTTP server from outside the Werkzeug project.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Palletsprojects Werkzeug | <=2.1.0 | |
<=2.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-29361.
The severity of CVE-2022-29361 is critical with a severity value of 9.8.
The affected software for CVE-2022-29361 is Pallets Werkzeug v2.1.0 and below.
The CWE ID associated with CVE-2022-29361 is CWE-444.
This vulnerability can be exploited by attackers to perform HTTP Request Smuggling using a crafted HTTP request with multiple requests included inside the body.