HomeGetlaminasCVE-2023-29530

CVE-2023-29530

HIGH
7.5CVSS
Published: 2023-04-24
Updated: 2024-11-21
AI Analysis

Description

Laminas Diactoros provides PSR HTTP Message implementations. In versions 2.18.0 and prior, 2.19.0, 2.20.0, 2.21.0, 2.22.0, 2.23.0, 2.24.0, and 2.25.0, users who create HTTP requests or responses using laminas/laminas-diactoros, when providing a newline at the start or end of a header key or value, can cause an invalid message. This can lead to denial of service vectors or application errors. The problem has been patched in following versions 2.18.1, 2.19.1, 2.20.1, 2.21.1, 2.22.1, 2.23.1, 2.24.1, and 2.25.1. As a workaround, validate HTTP header keys and/or values, and if using user-supplied values, filter them to strip off leading or trailing newline characters before calling `withHeader()`.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
network
Complexity
low
Privileges
none
User Action
none
Scope
unchanged
Confidentiality
none
Integrity
none
Availability
high
Weaknesses
CWE-20

Metadata

Primary Vendor
GETLAMINAS
Published
4/24/2023
Last Modified
11/21/2024
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

getlaminas : laminas-diactorosgetlaminas : laminas-diactorosgetlaminas : laminas-diactorosgetlaminas : laminas-diactorosgetlaminas : laminas-diactorosgetlaminas : laminas-diactorosgetlaminas : laminas-diactorosgetlaminas : laminas-diactorosguzzlephp : psr-7guzzlephp : psr-7fedoraproject : fedora

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2023-29530 | HIGH Severity | CVEDatabase.com | CVEDatabase.com