CRITICAL🇵🇱 Wersja polska

CVE-2022-38667

CVSS 9.8v3.1pub. 2022-08-22upd. 2024-11-21

HTTP applications (servers) based on Crow through 1.0+4 may allow a Use-After-Free and code execution when HTTP pipelining is used. The HTTP parser supports HTTP pipelining, but the asynchronous Connection layer is unaware of HTTP pipelining. Specifically, the Connection layer is unaware that it has begun processing a later request before it has finished processing an earlier request.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Crowcpp Crow

    APP
    Crowcpp
    ≤ 1.0\+4
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEMemory
CWE
References

Related vulnerabilities

CVE-2022-34970CRITICAL9.8PL ✓same product

Heap-based buffer overflow w Crow (RCE) przez funkcję qs_parse

CVE-2022-38668HIGH7.5same product

HTTP applications (servers) based on Crow through 1.0+4 may reveal potentially sensitive uninitialized data fr...

CVE-2023-26142MEDIUM6.5same product

All versions of the package crow are vulnerable to HTTP Response Splitting when untrusted user input is used t...

CVE-2021-23514MEDIUM6.5same product

This affects the package Crow before 0.3+4. It is possible to traverse directories to fetch arbitrary files fr...

CVE-2021-23824MEDIUM6.5same product

This affects the package Crow before 0.3+4. When using attributes without quotes in the template, an attacker ...