CVE-2021-23339
17.02.2021, 08:15
This affects all versions before 10.1.14 and from 10.2.0 to 10.2.4 of package com.typesafe.akka:akka-http-core. It allows multiple Transfer-Encoding headers.
Vendor | Product | Version |
---|---|---|
lightbend | akka-http | 𝑥 < 10.1.14 |
lightbend | akka-http | 10.2.0 ≤ 𝑥 < 10.2.4 |
𝑥
= Vulnerable software versions