GHSA-h385-52j6-9984

Suggest an improvement
Source
https://github.com/advisories/GHSA-h385-52j6-9984
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/10/GHSA-h385-52j6-9984/GHSA-h385-52j6-9984.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-h385-52j6-9984
Aliases
Withdrawn
2021-01-13T19:25:43Z
Published
2020-10-20T19:15:38Z
Modified
2026-09-10T03:48:58Z
Summary
Withdrawn: HTTP Request Smuggling in Agoo
Details

Withdrawn reason

Withdrawn on 1/13/2021 due to this comment from the maintainer. This is no longer considered a vulnerability.

Original description

agoo through 2.12.3 allows request smuggling attacks where agoo is used as a backend and a frontend proxy also being vulnerable. It is possible to conduct HTTP request smuggling attacks by sending the Content-Length header twice. Furthermore, invalid Transfer Encoding headers were found to be parsed as valid which could be leveraged for TE:CL smuggling attacks.

Database specific
{
    "cwe_ids": [
        "CWE-444"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2020-10-20T19:04:34Z",
    "nvd_published_at": null,
    "severity": "MODERATE"
}
References

Affected packages

RubyGems / agoo

Package

Name
agoo
Purl
pkg:gem/agoo

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
2.13.0

Affected versions

0.*
0.9.0
0.9.1
1.*
1.0.0
1.1.0
1.1.1
1.1.2
1.2.0
1.2.1
1.2.2
2.*
2.0.0
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.1.1
2.1.3
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.5.7
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.8.2
2.8.3
2.8.4
2.9.0
2.10.0
2.11.0
2.11.1
2.11.2
2.11.3
2.11.4
2.11.5
2.11.6
2.11.7
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/10/GHSA-h385-52j6-9984/GHSA-h385-52j6-9984.json"