CVE-2022-24775
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
21/03/2022
Last modified:
29/03/2022
Description
guzzlehttp/psr7 is a PSR-7 HTTP message library. Versions prior to 1.8.4 and 2.1.1 are vulnerable to improper header parsing. An attacker could sneak in a new line character and pass untrusted values. The issue is patched in 1.8.4 and 2.1.1. There are currently no known workarounds.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:* | 8.0.0 (including) | 9.2.16 (excluding) |
| cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:* | 9.3.0 (including) | 9.3.9 (excluding) |
| cpe:2.3:a:guzzlephp:psr-7:*:*:*:*:*:*:*:* | 1.8.4 (excluding) | |
| cpe:2.3:a:guzzlephp:psr-7:*:*:*:*:*:*:*:* | 2.0.0 (including) | 2.1.1 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



