CVE-2022-29361: Critical severity werkzeug vulnerability
DISPUTED Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perform HTTP Request Smuggling using a crafted HTTP request with multiple requests included inside the body. NOTE: the vendor's position is that this behavior can only occur in unsupported configurations involving development mode and an HTTP server from outside the Werkzeug project.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-29361.
What is the severity of CVE-2022-29361?
The severity of CVE-2022-29361 is critical with a severity value of 9.8.
What is the affected software for CVE-2022-29361?
The affected software for CVE-2022-29361 is Pallets Werkzeug v2.1.0 and below.
What is the CWE ID associated with CVE-2022-29361?
The CWE ID associated with CVE-2022-29361 is CWE-444.
How can this vulnerability be exploited?
This vulnerability can be exploited by attackers to perform HTTP Request Smuggling using a crafted HTTP request with multiple requests included inside the body.