An issue was discovered in the hyper crate before 0.12.34 for Rust. HTTP request smuggling can occur. Remote code execution can occur in certain situations with an HTTP server on the loopback interface.
References
Link Resource
https://rustsec.org/advisories/RUSTSEC-2020-0008.html Patch Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2020-12-31T08:29:46

Updated: 2020-12-31T08:29:46

Reserved: 2020-12-31T00:00:00


Link: CVE-2020-35863

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-12-31T10:15:15.097

Modified: 2021-07-21T11:39:23.747


Link: CVE-2020-35863

JSON object: View

cve-icon Redhat Information

No data.

CWE