bjoern@1.3.3 vulnerabilities

A screamingly fast Python 2 + 3 WSGI server written in C.

Direct Vulnerabilities

Known vulnerabilities in the bjoern package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
WSGI Header Spoofing

bjoern is a fast Python WSGI server written in C.

Affected versions of this package are vulnerable to WSGI header spoofing. A malicious user could exploit this vulnerability by using an _ character instead of a - in an HTTP header. In the WSGI environ, the X-Auth-User and the X-Auth_User headers are both converted to HTTP_X_Auth_User, allowing the attacker to bypass the protection. This vulnerability is related to CVE-2014-3566

[,1.4.2)