MEDIUM 5.4 Maven
Request smuggling is possible when both chunked TE and content length specified
GHSA-xrr9-rh8p-433v · CVE-2020-5207
Published · Modified
Description
Impact
Request smuggling is possible when running behind a proxy that doesn't handle Content-Length and Transfer-Encoding properly or doesn't handle alone \n as a headers separator.
Patches
https://github.com/ktorio/ktor/pull/1547
Workarounds
None except migrating to a better proxy.
References
https://portswigger.net/web-security/request-smuggling
https://tools.ietf.org/html/rfc7230#section-9.5
Ready to move
Start Securing
Free, no credit card | First findings in minutes