by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
4 packages
- perlPackages.CatalystXScriptServerStarman
- perl5Packages.CatalystXScriptServerStarman
- perl538Packages.CatalystXScriptServerStarman
- perl540Packages.CatalystXScriptServerStarman
- @LeSuisse ignored reference https://d…
- @LeSuisse accepted
- @LeSuisse published on GitHub
Starman versions before 0.4018 for Perl allows HTTP Request Smuggling via Improper Header Precedence
Starman versions before 0.4018 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Starman incorrectly prioritizes "Content-Length" over "Transfer-Encoding: chunked" when both headers are present in an HTTP request. Per RFC 7230 3.3.3, Transfer-Encoding must take precedence. An attacker could exploit this to smuggle malicious HTTP requests via a front-end reverse proxy.
References
Affected products
- <0.4018
Matching in nixpkgs
pkgs.perlPackages.Starman
High-performance preforking PSGI/Plack web server
pkgs.perl5Packages.Starman
High-performance preforking PSGI/Plack web server
pkgs.perl538Packages.Starman
High-performance preforking PSGI/Plack web server
pkgs.perl540Packages.Starman
High-performance preforking PSGI/Plack web server
Ignored packages (4)
pkgs.perlPackages.CatalystXScriptServerStarman
Replace the development server with Starman
pkgs.perl5Packages.CatalystXScriptServerStarman
Replace the development server with Starman
pkgs.perl538Packages.CatalystXScriptServerStarman
Replace the development server with Starman
pkgs.perl540Packages.CatalystXScriptServerStarman
Replace the development server with Starman