CVE-2023-34188

The HTTP server in Mongoose before 7.10 accepts requests containing negative Content-Length headers.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cesanta:mongoose:*:*:*:*:*:*:*:*

History

02 Dec 2024, 15:15

Type Values Removed Values Added
CWE CWE-1284

21 Nov 2024, 08:06

Type Values Removed Values Added
References () https://blog.narfindustries.com/blog/narf-discovers-critical-vulnerabilities-in-cesanta-mongoose-http-server - () https://blog.narfindustries.com/blog/narf-discovers-critical-vulnerabilities-in-cesanta-mongoose-http-server -
References () https://github.com/cesanta/mongoose/commit/4663090a8fb036146dfe77718cff612b0101cb0f - Patch () https://github.com/cesanta/mongoose/commit/4663090a8fb036146dfe77718cff612b0101cb0f - Patch
References () https://github.com/cesanta/mongoose/compare/7.9...7.10 - Release Notes () https://github.com/cesanta/mongoose/compare/7.9...7.10 - Release Notes
References () https://github.com/cesanta/mongoose/pull/2197 - Patch () https://github.com/cesanta/mongoose/pull/2197 - Patch

17 Jul 2023, 18:15

Type Values Removed Values Added
References
  • (MISC) https://blog.narfindustries.com/blog/narf-discovers-critical-vulnerabilities-in-cesanta-mongoose-http-server -

10 Jul 2023, 16:03

Type Values Removed Values Added
New CVE

Information

Published : 2023-06-23 20:15

Updated : 2024-12-02 15:15


NVD link : CVE-2023-34188

Mitre link : CVE-2023-34188

CVE.ORG link : CVE-2023-34188


JSON object : View

Products Affected

cesanta

  • mongoose
CWE
NVD-CWE-Other CWE-1284

Improper Validation of Specified Quantity in Input