Record summary

CVE-2019-6802 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

CRLF Injection in pypiserver 1.2.5 and below allows attackers to set arbitrary HTTP headers and possibly conduct XSS attacks via a %0d%0a in a URI.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
GitHub AdvisoryBefore 1.2.6 · Fixed in 1.2.6affected

Nuclei templates

1
ProjectDiscoveryMEDIUMPypiserver <1.2.5 - Carriage Return Line Feed InjectionCVSS 6.1

Pypiserver through 1.2.5 and below is susceptible to carriage return line feed injection. An attacker can set arbitrary HTTP headers and possibly conduct cross-site scripting attacks via a %0d%0a in a URI.

Impact

Attackers can inject arbitrary HTTP headers through CRLF injection, potentially conducting cross-site scripting attacks or cache poisoning.

Remediation

Upgrade to Pypiserver version 1.2.5 or later.

WeaknessesCWE-74
Authors0x_Akoko
Template tagscvecve2019crlfpypiserverpythonvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:python:pypiserver:*:*:*:*:*:*:*:*
Shodan: html:"pypiserver"
Shodan: http.html:"pypiserver"
FOFA: body="pypiserver"

Source: ProjectDiscovery

References

5