CVE-2023-22465

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-22465
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-22465.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-22465
Aliases
Withdrawn
2024-05-15T05:34:06.876042Z
Published
2023-01-04T16:15:09Z
Modified
2023-11-29T10:01:09.069663Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
Summary
[none]
Details

Http4s is a Scala interface for HTTP services. Starting with version 0.1.0 and prior to versions 0.21.34, 0.22.15, 0.23.17, and 1.0.0-M38, the User-Agent and Server header parsers are susceptible to a fatal error on certain inputs. In http4s, modeled headers are lazily parsed, so this only applies to services that explicitly request these typed headers. Fixes are released in 0.21.34, 0.22.15, 0.23.17, and 1.0.0-M38. As a workaround, use the weakly typed header interface.

References

Affected packages

Git / github.com/http4s/http4s

Affected versions

v0.*

v0.21.26
v0.21.27
v0.21.28
v0.21.29
v0.21.30
v0.21.31
v0.21.32
v0.21.33
v0.21.34
v0.22.10
v0.22.11
v0.22.12
v0.22.13
v0.22.14
v0.22.2
v0.22.3
v0.22.4
v0.22.5
v0.22.6
v0.22.7
v0.22.8
v0.22.9
v0.23.0
v0.23.1
v0.23.10
v0.23.11
v0.23.12
v0.23.13
v0.23.14
v0.23.15
v0.23.16
v0.23.2
v0.23.3
v0.23.4
v0.23.5
v0.23.6
v0.23.7
v0.23.8
v0.23.9