SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-22465

As a workaround, use the weakly typed header interface.

MEDIUM 5.3EPSS 0.84%

Does this matter?

Lower severity and a low EPSS score (0.84%). Track it; it rarely justifies an emergency change on its own.

Description

Http4s is a Scala interface for HTTP services. Starting with version 0.1.0 and prior to versions 0.21.34, 0.22.15, 0.23.17, and 1.0.0-M38, the `User-Agent` and `Server` header parsers are susceptible to a fatal error on certain inputs. In http4s, modeled headers are lazily parsed, so this only applies to services that explicitly request these typed headers. Fixes are released in 0.21.34, 0.22.15, 0.23.17, and 1.0.0-M38. As a workaround, use the weakly typed header interface.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
EPSS
0.84% probability · 56th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
typelevel/http4s
Source
security-advisories@github.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.