CVE-2022-38667
Summary
| CVE | CVE-2022-38667 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-08-22 20:15:00 UTC |
| Updated | 2022-10-28 19:04:00 UTC |
| Description | HTTP applications (servers) based on Crow through 1.0+4 may allow a Use-After-Free and code execution when HTTP pipelining is used. The HTTP parser supports HTTP pipelining, but the asynchronous Connection layer is unaware of HTTP pipelining. Specifically, the Connection layer is unaware that it has begun processing a later request before it has finished processing an earlier request. |
Risk And Classification
Problem Types: CWE-416
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Prevent HTTP pipelining by The-EDev · Pull Request #524 · CrowCpp/Crow · GitHub | MISC | github.com | |
| CVEs/CVE-2022-38667.md at main · 0xhebi/CVEs · GitHub | MISC | github.com | |
| CWE - CWE-372: Incomplete Internal State Distinction (4.7) | MISC | cwe.mitre.org | |
| Crow HTTP framework use-after-free - gynvael.coldwind//vx.log | MISC | gynvael.coldwind.pl | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.