CVE-2018-1000164
published 2018-04-18CVE-2018-1000164: gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers vulnerability in "process_headers" function in…
PriorityP342high7.5CVSS 3.0
AVNACLPRNUINSUCNIHAN
EPSS
2.45%
82.8th percentile
gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers vulnerability in "process_headers" function in "gunicorn/http/wsgi.py" that can result in an attacker causing the server to return arbitrary HTTP headers. This vulnerability appears to have been fixed in 19.5.0.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | gunicorn | < gunicorn 19.5.0-1 (bookworm) | gunicorn 19.5.0-1 (bookworm) |
| gunicorn | gunicorn | — | — |
| gunicorn | gunicorn | >= 0 < 19.5.0-1 | 19.5.0-1 |
| gunicorn | gunicorn | >= 0 < 19.5.0-1 | 19.5.0-1 |
| gunicorn | gunicorn | >= 0 < 19.5.0-1 | 19.5.0-1 |
| gunicorn | gunicorn | >= 0 < 19.5.0-1 | 19.5.0-1 |
| gunicorn | gunicorn | >= 0 < 19.5.0 | 19.5.0 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Gunicorn contains Improper Neutralization of CRLF sequences in HTTP headers
ghsa·2018-07-12
CVE-2018-1000164 [HIGH] CWE-93 Gunicorn contains Improper Neutralization of CRLF sequences in HTTP headers
Gunicorn contains Improper Neutralization of CRLF sequences in HTTP headers
gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers vulnerability in "process_headers" function in "gunicorn/http/wsgi.py" that can result in an attacker causing the server to return arbitrary HTTP headers. This vulnerability appears to have been fixed in 19.5.0.
OSV
Gunicorn contains Improper Neutralization of CRLF sequences in HTTP headers
osv·2018-07-12
CVE-2018-1000164 [HIGH] Gunicorn contains Improper Neutralization of CRLF sequences in HTTP headers
Gunicorn contains Improper Neutralization of CRLF sequences in HTTP headers
gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers vulnerability in "process_headers" function in "gunicorn/http/wsgi.py" that can result in an attacker causing the server to return arbitrary HTTP headers. This vulnerability appears to have been fixed in 19.5.0.
OSV
CVE-2018-1000164: gunicorn version 19
osv·2018-04-18·CVSS 7.5
CVE-2018-1000164 [HIGH] CVE-2018-1000164: gunicorn version 19
gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers vulnerability in "process_headers" function in "gunicorn/http/wsgi.py" that can result in an attacker causing the server to return arbitrary HTTP headers. This vulnerability appears to have been fixed in 19.5.0.
Ubuntu
Gunicorn vulnerability
vendor_ubuntu·2019-06-19
CVE-2018-1000164 Gunicorn vulnerability
Title: Gunicorn vulnerability
Summary: Gunicorn could allow cross-site scripting (XSS) attacks.
It was discovered that gunicorn improperly handled certain input. An attacker
could potentially use this issue execute a cross-site scripting (XSS) attack.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2018-1000164: gunicorn - gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of CRLF Sequ...
vendor_debian·2018·CVSS 7.5
CVE-2018-1000164 [HIGH] CVE-2018-1000164: gunicorn - gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of CRLF Sequ...
gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers vulnerability in "process_headers" function in "gunicorn/http/wsgi.py" that can result in an attacker causing the server to return arbitrary HTTP headers. This vulnerability appears to have been fixed in 19.5.0.
Scope: local
bookworm: resolved (fixed in 19.5.0-1)
bullseye: resolved (fixed in 19.5.0-1)
forky: resolved (fixed in 19.5.0-1)
sid: resolved (fixed in 19.5.0-1)
trixie: resolved (fixed in 19.5.0-1)
Red Hat
python-gunicorn: Improper neutralization of CRLF Sequences http/wsgi.py:process_headers() can allow an attacker to cause a server to return arbitrary HTTP headers
vendor_redhat·2016-03-17·CVSS 7.5
CVE-2018-1000164 [HIGH] CWE-113 python-gunicorn: Improper neutralization of CRLF Sequences http/wsgi.py:process_headers() can allow an attacker to cause a server to return arbitrary HTTP headers
python-gunicorn: Improper neutralization of CRLF Sequences http/wsgi.py:process_headers() can allow an attacker to cause a server to return arbitrary HTTP headers
gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers vulnerability in "process_headers" function in "gunicorn/http/wsgi.py" that can result in an attacker causing the server to return arbitrary HTTP headers. This vulnerability appears to have been fixed in 19.5.0.
Package: python-gunicorn (Red Hat Enterprise Linux 7) - Will not fix
Package: python-gunicorn (Red Hat OpenStack Platform 12 (Pike)) - Not affected
Package: python-gunicorn (Red Hat OpenStack Platform 13 (Queens)) - Not affected
Package: python-gunicorn (Red Hat Storage Console 2) - Will not fix
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-1000164 python-gunicorn: Improper neutralization of CRLF Sequences http/wsgi.py:process_headers() can allow an attacker to cause a server to return arbitrary HTTP headers
bugzilla·2018-04-09·CVSS 7.5
CVE-2018-1000164 [HIGH] CVE-2018-1000164 python-gunicorn: Improper neutralization of CRLF Sequences http/wsgi.py:process_headers() can allow an attacker to cause a server to return arbitrary HTTP headers
CVE-2018-1000164 python-gunicorn: Improper neutralization of CRLF Sequences http/wsgi.py:process_headers() can allow an attacker to cause a server to return arbitrary HTTP headers
python-gunicorn before version 19.5.0 has a HTTP response splitting vulnerability in the http/wsgi.py:process_headers() function caused by the improper neutralization of CRLF sequences. An attacker could exploit this to cause a server to return arbitrary HTTP headers.
External References:
https://epadillas.github.io/2018/04/02/http-header-splitting-in-gunicorn-19.4.5
Upstream Issue:
https://github.com/benoitc/gunicorn/issues/1227
Upstream Patch:
https://github.com/benoitc/gunicorn/commit/5263a4ef2a63c62216680876f3813959839608ff
Discussion:
Created python-gunicorn tracking bugs for this issue:
Affects
Bugzilla
CVE-2018-1000164 python-gunicorn: Improper neutralization of CRLF Sequences http/wsgi.py:process_headers() can allow an attacker to cause a server to return arbitrary HTTP headers [epel-6]
bugzilla·2018-04-09·CVSS 7.5
CVE-2018-1000164 [HIGH] CVE-2018-1000164 python-gunicorn: Improper neutralization of CRLF Sequences http/wsgi.py:process_headers() can allow an attacker to cause a server to return arbitrary HTTP headers [epel-6]
CVE-2018-1000164 python-gunicorn: Improper neutralization of CRLF Sequences http/wsgi.py:process_headers() can allow an attacker to cause a server to return arbitrary HTTP headers [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixe
https://epadillas.github.io/2018/04/02/http-header-splitting-in-gunicorn-19.4.5https://github.com/benoitc/gunicorn/issues/1227https://lists.debian.org/debian-lts-announce/2018/04/msg00022.htmlhttps://usn.ubuntu.com/4022-1/https://www.debian.org/security/2018/dsa-4186https://epadillas.github.io/2018/04/02/http-header-splitting-in-gunicorn-19.4.5https://github.com/benoitc/gunicorn/issues/1227https://lists.debian.org/debian-lts-announce/2018/04/msg00022.htmlhttps://usn.ubuntu.com/4022-1/https://www.debian.org/security/2018/dsa-4186
2018-04-18
Published