5
CVSSv2

CVE-2022-24775

Published: 21/03/2022 Updated: 29/03/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 446
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

guzzlehttp/psr7 is a PSR-7 HTTP message library. Versions before 1.8.4 and 2.1.1 are vulnerable to improper header parsing. An attacker could sneak in a new line character and pass untrusted values. The issue is patched in 1.8.4 and 2.1.1. There are currently no known workarounds.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

drupal drupal

guzzlephp psr-7

Vendor Advisories

Debian Bug report logs - #1034581 php-guzzlehttp-psr7: CVE-2023-29197 Package: src:php-guzzlehttp-psr7; Maintainer for src:php-guzzlehttp-psr7 is Debian PHP PEAR Maintainers <pkg-php-pear@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 18 Apr 2023 21:21:02 UTC Severity: impo ...
Debian Bug report logs - #1008236 php-guzzlehttp-psr7: CVE-2022-24775 Package: src:php-guzzlehttp-psr7; Maintainer for src:php-guzzlehttp-psr7 is Debian PHP PEAR Maintainers <pkg-php-pear@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 24 Mar 2022 22:03:02 UTC Severity: impo ...