HTTP Response Splitting Affecting gunicorn package, versions [,19.5.0)
Threat Intelligence
EPSS
0.49% (77th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-GUNICORN-42097
- published 25 Apr 2018
- disclosed 18 Apr 2018
- credit Unknown
Introduced: 18 Apr 2018
CVE-2018-1000164 Open this link in a new tabHow to fix?
Upgrade gunicorn
to version 19.5.0 or higher.
Overview
gunicorn is a WSGI HTTP Server for UNIX, fast clients and sleepy applications.
Affected versions of this package are vulnerable to HTTP Response Splitting in the process_headers
function.
References
CVSS Scores
version 3.1