CVE-2023-29530
Last modified
CVE-2023-29530 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Laminas Diactoros provides PSR HTTP Message implementations. In versions 2.18.0 and prior, 2.19.0, 2.20.0, 2.21.0, 2.22.0, 2.23.0, 2.24.0, and 2.25.0, users who create HTTP requests or responses using laminas/laminas-diactoros, when providing a newline at the start or end of a header key or value, can cause an invalid message. EPSS estimates a 0.97% chance of exploitation in the next 30 days.
Description
Laminas Diactoros provides PSR HTTP Message implementations. In versions 2.18.0 and prior, 2.19.0, 2.20.0, 2.21.0, 2.22.0, 2.23.0, 2.24.0, and 2.25.0, users who create HTTP requests or responses using laminas/laminas-diactoros, when providing a newline at the start or end of a header key or value, can cause an invalid message. This can lead to denial of service vectors or application errors. The problem has been patched in following versions 2.18.1, 2.19.1, 2.20.1, 2.21.1, 2.22.1, 2.23.1, 2.24.1, and 2.25.1. As a workaround, validate HTTP header keys and/or values, and if using user-supplied values, filter them to strip off leading or trailing newline characters before calling `withHeader()`.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Getlaminas | Laminas-Diactoros | < 2.18.1 |
| Getlaminas | Laminas-Diactoros | 2.19.0 |
| Getlaminas | Laminas-Diactoros | 2.20.0 |
| Getlaminas | Laminas-Diactoros | 2.21.0 |
| Getlaminas | Laminas-Diactoros | 2.22.0 |
| Getlaminas | Laminas-Diactoros | 2.23.0 |
| Getlaminas | Laminas-Diactoros | 2.24.0 |
| Getlaminas | Laminas-Diactoros | 2.25.0 |
| Guzzlephp | Psr-7 | < 1.9.1 |
| Guzzlephp | Psr-7 | >= 2.0.0, < 2.4.5 |
| Fedoraproject | Fedora | 38 |
References
- https://github.com/advisories/GHSA-wxmh-65f7-jcvwNot Applicable
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BPW54QK7ISDALPLP2CKODU4ZIVRYS336/Mailing List, Third Party Advisory
- https://github.com/advisories/GHSA-wxmh-65f7-jcvwNot Applicable
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BPW54QK7ISDALPLP2CKODU4ZIVRYS336/Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-29530?
How severe is CVE-2023-29530?
How do I fix CVE-2023-29530?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-29525XWiki Platform is a generic wiki platform offering runtime s…8.8
- CVE-2023-29526XWiki Platform is a generic wiki platform offering runtime s…8.8
- CVE-2023-29527XWiki Platform is a generic wiki platform offering runtime s…8.8
- CVE-2023-29528XWiki Commons are technical libraries common to several othe…9
- CVE-2023-29529matrix-js-sdk is the Matrix Client-Server SDK for JavaScript…5.3
- CVE-2023-2953A vulnerability was found in openldap. This security flaw ca…7.5
- CVE-2023-29531An attacker could have caused an out of bounds memory access…9.8
- CVE-2023-29532A local attacker can trick the Mozilla Maintenance Service i…5.5
- CVE-2023-29533A website could have obscured the fullscreen notification by…4.3
- CVE-2023-29534Different techniques existed to obscure the fullscreen notif…9.1
- CVE-2023-29535Following a Garbage Collector compaction, weak maps may have…6.5
- CVE-2023-29536An attacker could cause the memory manager to incorrectly fr…8.8
Are you affected by CVE-2023-29530?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
