CVE-2023-29530Improper Input Validation in Laminas-diactoros

Severity
6.5MEDIUMNVD
CNA7.5GHSA7.5OSV7.5
EPSS
0.2%
top 52.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 24

Description

Laminas Diactoros provides PSR HTTP Message implementations. In versions 2.18.0 and prior, 2.19.0, 2.20.0, 2.21.0, 2.22.0, 2.23.0, 2.24.0, and 2.25.0, users who create HTTP requests or responses using laminas/laminas-diactoros, when providing a newline at the start or end of a header key or value, can cause an invalid message. This can lead to denial of service vectors or application errors. The problem has been patched in following versions 2.18.1, 2.19.1, 2.20.1, 2.21.1, 2.22.1, 2.23.1, 2.24.1

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages4 packages

CVEListV5laminas/laminas-diactoros< 2.18.1+7
Packagistlaminas/laminas-diactoros2.19.02.19.1+7
NVDguzzlephp/psr-72.0.02.4.5+1

Also affects: Fedora 38

🔴Vulnerability Details

3
GHSA
HTTP Multiline Header Termination2023-04-24
CVEList
Laminas Diactoros vulnerable to HTTP Multiline Header Termination2023-04-24
OSV
HTTP Multiline Header Termination2023-04-24
CVE-2023-29530 — Improper Input Validation | cvebase