guzzlehttp/psr7 < 1.9.1 & 2.4.5 - Interpretation Conflict
medium
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Affected versions are subject to improper header parsing. An attacker could sneak in a newline (\n) into both the header names and values. While the specification states that \r\n\r\n is used to terminate the header list, many servers in the wild wi...
- CVSS:
- 5.3
- Affected:
- up to 3.2.2
- Fixed in:
- 3.2.2
- Disclosed:
- Apr 17, 2023
CVE-2023-29197 on NVD →
WP Offload Media Lite for Amazon S3, DigitalOcean Spaces, and Google Cloud Storage [amazon-s3-and-cloudfront] < 3.2.2
unknown
[en] guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Affected versions are subject to improper header parsing. An attacker could sneak in a newline (\n) into both the header names and values. While the specification states that \r\n\r\n is used to terminate the header list, many servers in the wi...
- Affected:
- up to 3.2.2
- Fixed in:
- 3.2.2
- Disclosed:
- Apr 17, 2023
CVE-2023-29197 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database