PyPi: Http-Tools

CVE-2021-39214

Transitive

Safety vulnerability ID: 60664

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Sep 16, 2021 Updated at Oct 27, 2024
Scan your Python projects for vulnerabilities →

Advisory

Http-tools 3.0.0 updates its dependency 'mitmproxy' to version '9.0.1' to include a fix for an HTTP Request Smuggling vulnerability.
https://github.com/MobSF/httptools/commit/896d06ab49b4eeb01353567c730afc32a380e99a

Affected package

http-tools

Latest version: 5.0.0

httptools helps you to capture, repeat and live intercept HTTP requests. It is built on top of [mitmproxy](https://mitmproxy.org/)

Affected versions

Fixed versions

Vulnerability changelog

* Bump mitmproxy to 9.0.1
* Minor bug fixes and code QA

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application

Severity Details

CVSS Base Score

CRITICAL 9.8

CVSS v3 Details

CRITICAL 9.8
Attack Vector (AV)
NETWORK
Attack Complexity (AC)
LOW
Privileges Required (PR)
NONE
User Interaction (UI)
NONE
Scope (S)
UNCHANGED
Confidentiality Impact (C)
HIGH
Integrity Impact (I)
HIGH
Availability Availability (A)
HIGH

CVSS v2 Details

HIGH 7.5
Access Vector (AV)
NETWORK
Access Complexity (AC)
LOW
Authentication (Au)
NONE
Confidentiality Impact (C)
PARTIAL
Integrity Impact (I)
PARTIAL
Availability Impact (A)
PARTIAL