VulnerabilityModified
CVE-2020-7655
netius prior to 1.17.58 is vulnerable to HTTP Request Smuggling.
MEDIUM 6.1EPSS 0.82%
Does this matter?
Lower severity and a low EPSS score (0.82%). Track it; it rarely justifies an emergency change on its own.
Description
netius prior to 1.17.58 is vulnerable to HTTP Request Smuggling. HTTP pipelining issues and request smuggling attacks might be possible due to incorrect Transfer encoding header parsing which could allow for CL:TE or TE:TE attacks.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.82% probability · 55th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-444
- Affected
- hive/netius
- Source
- report@snyk.io
References
- https://snyk.io/vuln/SNYK-PYTHON-NETIUS-569141Patch, Third Party Advisory
- https://snyk.io/vuln/SNYK-PYTHON-NETIUS-569141Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.