Improper Input Validation Affecting gunicorn package, versions [,19.4.0)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-GUNICORN-1090281
- published 1 Apr 2021
- disclosed 1 Apr 2021
- credit Unknown
How to fix?
Upgrade gunicorn
to version 19.4.0 or higher.
Overview
gunicorn is a Python WSGI HTTP Server for UNIX
Affected versions of this package are vulnerable to Improper Input Validation. Gunicorn fails with a 500, instead of a 400, when a request path is a malformed IPv6 address. This is due to no raise 'InvalidRequestLine' exception when the line contains malicious data.
References
CVSS Scores
version 3.1