Input validation error in HTTPie CLI - CVE-2019-10751
Published: September 4, 2019
Vulnerability identifier: #VU20851
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-10751
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to create arbitrary files on the system.
The vulnerability exists due to HTTPie utility does not properly processes URL redirects. A remote attacker can create arbitrary files with arbitrary content in the current directory.
Affected software
HTTPie CLI
httpie (Alpine package)
httpie
Fedora
SUSE Linux
Opensuse
httpie (Alpine package)
httpie
Fedora
SUSE Linux
Opensuse
How to mitigate CVE-2019-10751
Install updates from vendor's website.
HTTPie CLI - update to 1.0.3
httpie (Alpine package) - update to 1.0.3-r0
httpie - update to 1.0.3-1.el7
httpie (Alpine package) - update to 1.0.3-r0
httpie - update to 1.0.3-1.el7