« Volver al listado

CVE-2021-39185

Estado: ModificadaCrítica (9.1)—

Http4s is a minimal, idiomatic Scala interface for HTTP services. In http4s versions 0.21.26 and prior, 0.22.0 through 0.22.2, 0.23.0, 0.23.1, and 1.0.0-M1 through 1.0.0-M24, the default CORS configuration is vulnerable to an origin reflection attack. The middleware is also susceptible to a Null Origin Attack. The problem is fixed in 0.21.27, 0.22.3, 0.23.2, and 1.0.0-M25. The original `CORS` implementation and `CORSConfig` are deprecated. See the GitHub GHSA for more information, including code examples and workarounds.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-39185",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.1,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "http4s",
          "product": "http4s",
          "versions": [
            {
              "status": "affected",
              "version": "< 0.21.27"
            },
            {
              "status": "affected",
              "version": ">= 0.22.0, < 0.22.3"
            },
            {
              "status": "affected",
              "version": ">= 0.23.0, < 0.23.2"
            },
            {
              "status": "affected",
              "version": ">= 1.0.0-M1, <= 1.0.0-M24"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-09-01T20:15:07.447",
  "references": [
    {
      "url": "https://github.com/http4s/http4s/releases/tag/v0.23.2",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/http4s/http4s/security/advisories/GHSA-52cf-226f-rhr6",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/http4s/http4s/releases/tag/v0.23.2",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/http4s/http4s/security/advisories/GHSA-52cf-226f-rhr6",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-346"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Http4s is a minimal, idiomatic Scala interface for HTTP services. In http4s versions 0.21.26 and prior, 0.22.0 through 0.22.2, 0.23.0, 0.23.1, and 1.0.0-M1 through 1.0.0-M24, the default CORS configuration is vulnerable to an origin reflection attack. The middleware is also susceptible to a Null Origin Attack. The problem is fixed in 0.21.27, 0.22.3, 0.23.2, and 1.0.0-M25. The original `CORS` implementation and `CORSConfig` are deprecated. See the GitHub GHSA for more information, including code examples and workarounds."
    },
    {
      "lang": "es",
      "value": "Http4s es una interfaz mínima e idiomática de Scala para servicios HTTP. En http4s versiones 0.21.26 y anteriores, 0.22.0 hasta 0.22.2, 0.23.0, 0.23.1, y 1.0.0-M1 hasta 1.0.0-M24, la configuración CORS predeterminada es vulnerable a un ataque de reflexión de origen. El middleware también es susceptible a un ataque de Origen Nulo. El problema se ha corregido en las versiones 0.21.27, 0.22.3, 0.23.2 y 1.0.0-M25. La implementación original de \"CORS\" y \"CORSConfig\" están obsoletas. Consulte el GHSA de GitHub para conseguir más información, incluyendo ejemplos de código y soluciones"
    }
  ],
  "lastModified": "2026-06-17T04:03:16.257",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:typelevel:http4s:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EA68C82D-88CA-4315-9FF9-DA0FE8223156",
              "versionEndIncluding": "0.21.26"
            },
            {
              "criteria": "cpe:2.3:a:typelevel:http4s:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B4F97B04-29A9-4A32-BFC8-E971B72596F6",
              "versionEndIncluding": "0.22.2",
              "versionStartIncluding": "0.22.0"
            },
            {
              "criteria": "cpe:2.3:a:typelevel:http4s:0.23.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "40C64FD8-E742-4D74-BCCD-C585A7E05A70"
            },
            {
              "criteria": "cpe:2.3:a:typelevel:http4s:0.23.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AB9E400F-E915-4E63-B580-F54C32CC8FA1"
            },
            {
              "criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "65C497F9-281C-4565-BD36-B6B4D7E6F8BD"
            },
            {
              "criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone10:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6FCFC3E5-7530-4AAA-A2C7-36DC307B613B"
            },
            {
              "criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone11:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D03CBFE3-0B31-4D7C-BC5D-61DCD3C2C486"
            },
            {
              "criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone12:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "76F8BC53-544C-4285-8D9B-CB91AD080048"
            },
            {
              "criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone13:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "778947CA-20BA-469F-87E1-97D8713ACC75"
            },
            {
              "criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone14:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F5B02828-1E40-49BE-8367-10296625C696"
            },
            {
              "criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone15:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A569F32F-3C8C-4F8F-B0BC-6ADC993596A9"
            },
            {
              "criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone16:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "525DBF4B-F574-459D-9CE2-6AF597ABAE10"
            },
            {
              "criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone17:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FD05B15E-1E4F-43EA-B21A-3B96A77814D6"
            },
            {
              "criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone18:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "65C79F52-F05F-4F0A-AC27-393197B9EF00"
            },
            {
              "criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone19:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A426B4C0-643A-492F-B7FB-725549F613F6"
            },
            {
              "criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D95E231C-3D13-45FC-AF9A-CB8CF1FFC983"
            },
            {
              "criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone20:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CF973F58-0AC7-4B58-A2CF-654133CE7F1A"
            },
            {
              "criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone21:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "35C40331-C96C-477C-B6BD-D5506E612DA8"
            },
            {
              "criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone22:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "615BC827-3E0F-4C1E-8FD2-B59FF31F2D49"
            },
            {
              "criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone23:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FDFB35FD-4D08-4895-B1B6-FC03BCB3EB22"
            },
            {
              "criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone24:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "97F74D04-031E-47D4-BA57-DBE9C74CE256"
            },
            {
              "criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DE093D65-1B3A-4A4A-BC76-05DEF9529712"
            },
            {
              "criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DC3CA618-148D-4F97-9913-316DDDD97838"
            },
            {
              "criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "02FA538C-9D8A-49D5-8268-1A2C3E96B89B"
            },
            {
              "criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D18A3ABC-5C47-45BF-978C-5BB17787DCFA"
            },
            {
              "criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1CE1CF51-E61A-418A-AB22-9D7A6D690BAA"
            },
            {
              "criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone8:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "29A70AAA-B77A-4291-A700-C910362DB8D4"
            },
            {
              "criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone9:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9F8F3C38-57AB-4CBC-8959-7FF51CBA7907"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}