Waitress through version 1.3.1 allows request smuggling by sending the Content-Length header twice. Waitress would header fold a double Content-Length header and due to being unable to cast the now comma separated value to an integer would set the Content-Length to 0 internally. If two Content-Length headers are sent in a single request, Waitress would treat the request as having no body, thereby treating the body of the request as a new request in HTTP pipelining. This issue is fixed in Waitress 1.4.0.
CVSS Details
- CVSS 3.1 Base Score: 7.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade waitress | May 16, 2022 | Jan 22, 2020 |
| Oracle Solaris | — | Upgrade legacy/library/python/waitress-35 to version 1.4.3-11.4.21.0.1.69.0 on Solaris 11.4Upgrade library/python-2/waitress to version 0.8.5-11.4.0.0.1.9.0 on Solaris 11.4Upgrade library/python-2/waitress-27 to version 0.8.5-11.4.0.0.1.9.0 on Solaris 11.4Upgrade library/python/waitress-34 to version 1.4.3-11.4.21.0.1.69.0 on Solaris 11.4Upgrade library/python/waitress-35 to version 1.4.3-11.4.21.0.1.69.0 on Solaris 11.4Upgrade library/python/waitress-27 to version 1.4.3-11.4.21.0.1.69.0 on Solaris 11.4Upgrade library/python/waitress-26 to version 0.8.5-11.4.0.0.1.9.0 on Solaris 11.4Upgrade library/python/waitress to version 1.4.3-11.4.21.0.1.69.0 on Solaris 11.4Upgrade legacy/library/python/waitress-34 to version 1.4.3-11.4.21.0.1.69.0 on Solaris 11.4Upgrade library/python-2/waitress-26 to version 0.8.5-11.4.0.0.1.9.0 on Solaris 11.4 | Jan 19, 2021 | Jan 22, 2020 |
| Suse | — | Upgrade python2-waitressUpgrade python3-waitress | Nov 12, 2020 | Jan 22, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub