Horizon Alert
Summary of the vulnerability and why it matters
A vulnerability exists in http4s, a Scala interface for HTTP services, related to how it handles specific message headers. This could allow an unauthenticated attacker to potentially bypass access controls, poison caches, or manipulate requests forwarded by intermediaries. The main concern is confirming if our environment utilizes the affected versions of http4s.
- Unexpected header behavior allows request manipulation.
- Risk of bypassed access controls and cache poisoning.
- Confirm if affected http4s versions are in use.
Attack Path
How an attacker could exploit the issue
An attacker could exploit this vulnerability by sending specially crafted HTTP messages to a server running a vulnerable version of http4s, especially when it's behind a keep-alive intermediary. This could allow them to bypass access controls, manipulate cached content, or disrupt legitimate user requests.
- Requires network access and no privileges.
- Triggers by sending combined `Transfer-Encoding` and `Content-Length` headers.
- Allows request smuggling and cache poisoning.
Live Threat
Current exploitation, exposure, and threat context
When intermediary servers and http4s's Ember HTTP/1.1 disagree on how to frame HTTP messages, an attacker could potentially smuggle a second request. This could allow them to bypass access controls, poison caches, or manipulate a victim's request. The vulnerability could also affect http4s client connections when interacting with a malicious upstream server.
- Server and client communication.
- Request header processing.
- Bypassed access controls.
Operational Fix
Recommended remediation, mitigation, and detection steps
Technical leaders and system owners should engage platform or application teams responsible for services built with http4s. The first practical step is to identify all deployments of http4s, determine their reachability and criticality, and then assign an accountable owner to plan remediation.
- Platform/application teams own the issue.
- Verify http4s deployment reachability and criticality.
- Plan remediation based on identified risk.