CVE-2023-22465
Summary
| CVE | CVE-2023-22465 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-01-04 16:15:00 UTC |
| Updated | 2023-11-07 04:06:00 UTC |
| Description | Http4s is a Scala interface for HTTP services. Starting with version 0.1.0 and prior to versions 0.21.34, 0.22.15, 0.23.17, and 1.0.0-M38, the `User-Agent` and `Server` header parsers are susceptible to a fatal error on certain inputs. In http4s, modeled headers are lazily parsed, so this only applies to services that explicitly request these typed headers. Fixes are released in 0.21.34, 0.22.15, 0.23.17, and 1.0.0-M38. As a workaround, use the weakly typed header interface. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Typelevel | Http4s | All | All | All | All |
| Application | Typelevel | Http4s | 1.0.0 | milestone1 | All | All |
| Application | Typelevel | Http4s | 1.0.0 | milestone10 | All | All |
| Application | Typelevel | Http4s | 1.0.0 | milestone11 | All | All |
| Application | Typelevel | Http4s | 1.0.0 | milestone12 | All | All |
| Application | Typelevel | Http4s | 1.0.0 | milestone13 | All | All |
| Application | Typelevel | Http4s | 1.0.0 | milestone14 | All | All |
| Application | Typelevel | Http4s | 1.0.0 | milestone15 | All | All |
| Application | Typelevel | Http4s | 1.0.0 | milestone16 | All | All |
| Application | Typelevel | Http4s | 1.0.0 | milestone17 | All | All |
| Application | Typelevel | Http4s | 1.0.0 | milestone18 | All | All |
| Application | Typelevel | Http4s | 1.0.0 | milestone19 | All | All |
| Application | Typelevel | Http4s | 1.0.0 | milestone2 | All | All |
| Application | Typelevel | Http4s | 1.0.0 | milestone20 | All | All |
| Application | Typelevel | Http4s | 1.0.0 | milestone21 | All | All |
| Application | Typelevel | Http4s | 1.0.0 | milestone22 | All | All |
| Application | Typelevel | Http4s | 1.0.0 | milestone23 | All | All |
| Application | Typelevel | Http4s | 1.0.0 | milestone24 | All | All |
| Application | Typelevel | Http4s | 1.0.0 | milestone25 | All | All |
| Application | Typelevel | Http4s | 1.0.0 | milestone26 | All | All |
| Application | Typelevel | Http4s | 1.0.0 | milestone27 | All | All |
| Application | Typelevel | Http4s | 1.0.0 | milestone28 | All | All |
| Application | Typelevel | Http4s | 1.0.0 | milestone29 | All | All |
| Application | Typelevel | Http4s | 1.0.0 | milestone3 | All | All |
| Application | Typelevel | Http4s | 1.0.0 | milestone30 | All | All |
| Application | Typelevel | Http4s | 1.0.0 | milestone31 | All | All |
| Application | Typelevel | Http4s | 1.0.0 | milestone32 | All | All |
| Application | Typelevel | Http4s | 1.0.0 | milestone33 | All | All |
| Application | Typelevel | Http4s | 1.0.0 | milestone34 | All | All |
| Application | Typelevel | Http4s | 1.0.0 | milestone35 | All | All |
| Application | Typelevel | Http4s | 1.0.0 | milestone36 | All | All |
| Application | Typelevel | Http4s | 1.0.0 | milestone37 | All | All |
| Application | Typelevel | Http4s | 1.0.0 | milestone4 | All | All |
| Application | Typelevel | Http4s | 1.0.0 | milestone5 | All | All |
| Application | Typelevel | Http4s | 1.0.0 | milestone6 | All | All |
| Application | Typelevel | Http4s | 1.0.0 | milestone7 | All | All |
| Application | Typelevel | Http4s | 1.0.0 | milestone8 | All | All |
| Application | Typelevel | Http4s | 1.0.0 | milestone9 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Fatal error parsing User-Agent and Server headers · Advisory · http4s/http4s · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.