CVE-2020-7670

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/06/2020
Last modified:
17/11/2020

Description

agoo prior to 2.14.0 allows request smuggling attacks where agoo is used as a backend and a frontend proxy also being vulnerable. HTTP pipelining issues and request smuggling attacks might be possible due to incorrect Content-Length and Transfer encoding header parsing. It is possible to conduct HTTP request smuggling attacks where `agoo` is used as part of a chain of backend servers due to insufficient `Content-Length` and `Transfer Encoding` parsing.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ohler:agoo:*:*:*:*:*:ruby:*:* 2.12.3 (including)