Kodek HTTP/2-to-HTTP/1.1 w swift-nio-http2 nie weryfikował znaków sterujących w wartościach pseudo-nagłówków przed umieszczeniem ich w przetłumaczonym komunikacie HTTP/1.1. Swift-nio-http2 1.44.1 dodaje walidację wszystkich wartości pseudo-nagłówków (:path, :authority, :scheme, :method i :status) zarówno na poziomie walidacji HPACK, jak i w warstwie translacji HTTP/2-to-HTTP/1.1. Żądania lub odpowiedzi zawierające bajty CR, LF lub NUL w dowolnej wartości pseudo-nagłówka są teraz odrzucane z błędem połączenia. Problem został rozwiązany w wersji swift-nio-http2 1.44.1.
▸ Pokaż oryginał (EN)
swift-nio-http2's HTTP/2-to-HTTP/1.1 codec did not validate pseudo-header values for control characters before placing them into the translated HTTP/1.1 message. swift-nio-http2 1.44.1 adds validation of all pseudo-header values (:path, :authority, :scheme, :method, and :status) at both the HPACK header validation layer and the HTTP/2-to-HTTP/1.1 translation layer. Requests or responses containing CR, LF, or NUL bytes in any pseudo-header value are now rejected with a connection error. This issue is fixed in swift-nio-http2 1.44.1.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NApple Swiftnio Http\/2
APPApple< 1.44.1
Powiązane podatności
A program using swift-nio-http2 is vulnerable to a denial of service attack, caused by a network peer sending ...
A program using swift-nio-http2 is vulnerable to a denial of service attack, caused by a network peer sending ...
A program using swift-nio-http2 is vulnerable to a denial of service attack, caused by a network peer sending ...
A program using swift-nio-http2 is vulnerable to a denial of service attack caused by a network peer sending A...
SwiftNIO HTTP/2 nie walidował poprawnie przychodzących ramek HEADERS, co pozwalało znakom CR, LF, NUL, SP i in...