First published: Thu Mar 05 2020(Updated: )
Waitress is a pure Python WSGI server which supports HTTP/1.0 and HTTP/1.1.<br>Security Fix(es):<br><li> HTTP request smuggling through LF vs CRLF handling (CVE-2019-16785)</li> <li> HTTP request smuggling through invalid Transfer-Encoding (CVE-2019-16786)</li> <li> HTTP Request Smuggling through Invalid whitespace characters in headers</li> (CVE-2019-16789)<br>For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/python-waitress | <1.4.2-1.el8 | 1.4.2-1.el8 |
redhat/python3-waitress | <1.4.2-1.el8 | 1.4.2-1.el8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.