GSD-2022-1002524

Import Source
https://github.com/cloudsecurityalliance/gsd-database/blob/main/2022/1002xxx/GSD-2022-1002524.json
Withdrawn
2023-03-14T07:01:09.292516Z
Published
2022-05-30T16:26:29.213070Z
Modified
2023-03-14T07:01:09.292516Z
Details

In Amazon Elastic Load Balancer (ELB) prior to 2022-01-29 when "Legacy cache settings" is enabled an input validation (CWE-20) vulnerability exists in the HTTP Header processing that can be attacked via the network (using a trailing space in the requests) resulting in HTTP Header Smuggling.

References

Affected packages