CVE-2022-29361
Summary
| CVE | CVE-2022-29361 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-05-25 01:15:00 UTC |
| Updated | 2023-11-07 03:46:00 UTC |
| Description | ** DISPUTED ** Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perform HTTP Request Smuggling using a crafted HTTP request with multiple requests included inside the body. NOTE: the vendor's position is that this behavior can only occur in unsupported configurations involving development mode and an HTTP server from outside the Werkzeug project. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Question regarding CVE-2022-29361 · Issue #2420 · pallets/werkzeug · GitHub |
MISC |
github.com |
|
| Merge branch '2.0.x' · pallets/werkzeug@9a3a981 · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 502926 Alpine Linux Security Update for py3-werkzeug
- 505805 Alpine Linux Security Update for py3-werkzeug