Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Important] HTTP Request Smuggling #217

Open
ostpachukAndrii opened this issue May 15, 2024 · 0 comments
Open

[Important] HTTP Request Smuggling #217

ostpachukAndrii opened this issue May 15, 2024 · 0 comments

Comments

@ostpachukAndrii
Copy link

Dear Whisper-ASR-Webservice Team,

I hope this message finds you well.

I regret to inform you that a critical security vulnerability has been identified in one of service dependencies, specifically gunicorn version 21.2.0. It is imperative that we upgrade to version 22.0.0 immediately to address this issue.

The vulnerability in question pertains to HTTP Request Smuggling, resulting from improper validation of Transfer-Encoding headers within affected versions. This flaw could potentially enable attackers to circumvent security measures and gain unauthorized access to restricted endpoints by crafting requests with conflicting Transfer-Encoding headers.

Given the severity of this issue, I urge everyone to prioritize the update process without delay.

Thank you for your swift attent!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant