CVE-2021-38512

An issue was discovered in the actix-http crate before 3.0.0-beta.9 for Rust. HTTP/1 request smuggling (aka HRS) can occur, potentially leading to credential disclosure.
Configurations

Configuration 1

cpe:2.3:a:actix:actix-http:3.0.0:beta1:*:*:*:rust:*:*
cpe:2.3:a:actix:actix-http:3.0.0:beta2:*:*:*:rust:*:*
cpe:2.3:a:actix:actix-http:3.0.0:beta3:*:*:*:rust:*:*
cpe:2.3:a:actix:actix-http:3.0.0:beta4:*:*:*:rust:*:*
cpe:2.3:a:actix:actix-http:3.0.0:beta5:*:*:*:rust:*:*
cpe:2.3:a:actix:actix-http:3.0.0:beta6:*:*:*:rust:*:*
cpe:2.3:a:actix:actix-http:*:*:*:*:*:rust:*:*
cpe:2.3:a:actix:actix-http:3.0.0:-:*:*:*:rust:*:*
cpe:2.3:a:actix:actix-http:3.0.0:beta7:*:*:*:rust:*:*
cpe:2.3:a:actix:actix-http:3.0.0:beta8:*:*:*:rust:*:*
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*

Information

Published : 2021-08-10 11:15

Updated : 2021-09-21 05:10


NVD link : CVE-2021-38512

Mitre link : CVE-2021-38512

Products Affected
No products.
CWE
CWE-444

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')