CVE-2022-24761 - log back

CVE-2022-24761 created at 18 May 2022 19:08:36
Severity
+ High
Remote
+ Remote
Type
+ Unknown
Description
+ waitress behind a proxy that does not properly validate the incoming HTTP request matches the RFC7230 is vulnerable to request smuggling due to a disagreement between waitress and the proxy on where one request starts and where it ends.
References
+ https://github.com/Pylons/waitress/commit/9e0b8c801e4d505c2ffc91b891af4ba48af715e0
+ https://github.com/Pylons/waitress/security/advisories/GHSA-4f7p-27jc-3c36
+ https://github.com/Pylons/waitress/releases/tag/v2.1.1
Notes