Show plain JSON{"id": "CVE-2020-7655", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 4.3, "accessVector": "NETWORK", "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "MEDIUM", "availabilityImpact": "NONE", "confidentialityImpact": "NONE"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 8.6, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true}], "cvssMetricV31": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "CHANGED", "version": "3.1", "baseScore": 6.1, "attackVector": "NETWORK", "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "integrityImpact": "LOW", "userInteraction": "REQUIRED", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "NONE", "confidentialityImpact": "LOW"}, "impactScore": 2.7, "exploitabilityScore": 2.8}]}, "published": "2020-05-21T15:15:09.890", "references": [{"url": "https://snyk.io/vuln/SNYK-PYTHON-NETIUS-569141", "tags": ["Patch", "Third Party Advisory"], "source": "report@snyk.io"}, {"url": "https://snyk.io/vuln/SNYK-PYTHON-NETIUS-569141", "tags": ["Patch", "Third Party Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-444"}]}], "descriptions": [{"lang": "en", "value": "netius prior to 1.17.58 is vulnerable to HTTP Request Smuggling. HTTP pipelining issues and request smuggling attacks might be possible due to incorrect Transfer encoding header parsing which could allow for CL:TE or TE:TE attacks."}, {"lang": "es", "value": "netius versiones anteriores a la versi\u00f3n 1.17.58, es vulnerable a un ataque de tr\u00e1fico no autorizado de Peticiones HTTP. Los problemas de canalizaci\u00f3n de HTTP y los ataques de tr\u00e1fico no autorizado de peticiones podr\u00edan ser posibles debido a un an\u00e1lisis de encabezado de codificaci\u00f3n Transfer incorrecto que podr\u00eda permitir ataques de tipo CL:TE o TE:TE."}], "lastModified": "2024-11-21T05:37:33.110", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:hive:netius:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "917182B3-1CCE-4B4F-BC76-E2FAB68E5F07", "versionEndExcluding": "1.17.58"}], "operator": "OR"}]}], "sourceIdentifier": "report@snyk.io"}