VDB

CVE-2021-39214

CVE-2021-39214 PUBLISHED CVSS 9.300000190734863 CRITICAL

mitmproxy is an interactive, SSL/TLS-capable intercepting proxy. In mitmproxy 7.0.2 and below, a malicious client or server is able to perform HTTP request smuggling attacks through mitmproxy. This means that a malicious client/server could smuggle a request/response through mitmproxy as part of another request/response's HTTP message body. While a smuggled request is still captured as part of another request's body, it does not appear in the request list and does not go through the usual mitmproxy event hooks, where users may have implemented custom access control checks or input sanitization. Unless one uses mitmproxy to protect an HTTP/1 service, no action is required. The vulnerability has been fixed in mitmproxy 7.0.3 and above.

EPSS 1.05% · 61.5th percentile

Risk Scores

CVSS 4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS Score
1.05%
61.5th percentile

Affected Products

VendorProductVersions
mitmproxymitmproxy0, *
PyPImitmproxy0

Timeline

  • Sep 16, 2021 CVE Published
  • Sep 17, 2021 EPSS Score
  • Oct 5, 2021 EPSS Score
  • Oct 11, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Jan 10, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Mar 9, 2022 EPSS Score
  • May 5, 2022 EPSS Score
  • Jul 2, 2022 EPSS Score
  • Aug 29, 2022 EPSS Score
  • Oct 26, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›