CVE-2021-38512
published 2021-08-10CVE-2021-38512: An issue was discovered in the actix-http crate before 3.0.0-beta.9 for Rust. HTTP/1 request smuggling (aka HRS) can occur, potentially leading to credential…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.81%
76.5th percentile
An issue was discovered in the actix-http crate before 3.0.0-beta.9 for Rust. HTTP/1 request smuggling (aka HRS) can occur, potentially leading to credential disclosure.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| actix | actix-http | < 3.0.0 | 3.0.0 |
| actix | actix-http | — | — |
| actix | actix-http | >= 0 < 2.2.1 | 2.2.1 |
| actix | actix-http | >= 0.0.0-0 < 2.2.1 | 2.2.1 |
| actix | actix-http | >= 3.0.0-0 < 3.0.0-beta.9 | 3.0.0-beta.9 |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
HTTP Request Smuggling in actix-http
ghsa·2021-08-25
CVE-2021-38512 [HIGH] CWE-444 HTTP Request Smuggling in actix-http
HTTP Request Smuggling in actix-http
Affected versions of this crate did not properly detect invalid requests that could allow HTTP/1 request smuggling (HRS) attacks when running alongside a vulnerable front-end proxy server. This can result in leaked internal and/or user data, including credentials, when the front-end proxy is also vulnerable.
Popular front-end proxies and load balancers already mitigate HRS attacks so it is recommended that they are also kept up to date; check your specific set up. You should upgrade even if the front-end proxy receives exclusively HTTP/2 traffic and connects to the back-end using HTTP/1; several downgrade attacks are known that can also expose HRS vulnerabilities.
OSV
HTTP Request Smuggling in actix-http
osv·2021-08-25
CVE-2021-38512 [HIGH] HTTP Request Smuggling in actix-http
HTTP Request Smuggling in actix-http
Affected versions of this crate did not properly detect invalid requests that could allow HTTP/1 request smuggling (HRS) attacks when running alongside a vulnerable front-end proxy server. This can result in leaked internal and/or user data, including credentials, when the front-end proxy is also vulnerable.
Popular front-end proxies and load balancers already mitigate HRS attacks so it is recommended that they are also kept up to date; check your specific set up. You should upgrade even if the front-end proxy receives exclusively HTTP/2 traffic and connects to the back-end using HTTP/1; several downgrade attacks are known that can also expose HRS vulnerabilities.
OSV
Potential request smuggling capabilities due to lack of input validation
osv·2021-06-16
CVE-2021-38512 Potential request smuggling capabilities due to lack of input validation
Potential request smuggling capabilities due to lack of input validation
Affected versions of this crate did not properly detect invalid requests that could allow HTTP/1 request smuggling (HRS) attacks when running alongside a vulnerable front-end proxy server. This can result in leaked internal and/or user data, including credentials, when the front-end proxy is also vulnerable.
Popular front-end proxies and load balancers already mitigate HRS attacks so it is recommended that they are also kept up to date; check your specific set up. You should upgrade even if the front-end proxy receives exclusively HTTP/2 traffic and connects to the back-end using HTTP/1; several downgrade attacks are known that can also expose HRS vulnerabilities.
Red Hat
rust-actix-http: potential request smuggling capabilities due to lack of input validation
vendor_redhat·2021-06-16·CVSS 7.5
CVE-2021-38512 [HIGH] CWE-20 rust-actix-http: potential request smuggling capabilities due to lack of input validation
rust-actix-http: potential request smuggling capabilities due to lack of input validation
An issue was discovered in the actix-http crate before 3.0.0-beta.9 for Rust. HTTP/1 request smuggling (aka HRS) can occur, potentially leading to credential disclosure.
Package: cincinnati-container (Red Hat Advanced Cluster Management for Kubernetes 2) - Not affected
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/67URRW4K47SR6LNQB4YALPLGGQMQK7HO/https://raw.githubusercontent.com/rustsec/advisory-db/main/crates/actix-http/RUSTSEC-2021-0081.mdhttps://rustsec.org/advisories/RUSTSEC-2021-0081.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/67URRW4K47SR6LNQB4YALPLGGQMQK7HO/https://raw.githubusercontent.com/rustsec/advisory-db/main/crates/actix-http/RUSTSEC-2021-0081.mdhttps://rustsec.org/advisories/RUSTSEC-2021-0081.html
2021-08-10
Published