{"id":"GHSA-h385-52j6-9984","summary":"Withdrawn: HTTP Request Smuggling in Agoo","details":"# Withdrawn reason\nWithdrawn on 1/13/2021 due to [this comment from the maintainer](https://github.com/ohler55/agoo/issues/88#issuecomment-723580783).  This is no longer considered a vulnerability.\n\n# Original description\nagoo through 2.12.3 allows request smuggling attacks where agoo is used as a backend and a frontend proxy also being vulnerable. It is possible to conduct HTTP request smuggling attacks by sending the Content-Length header twice. Furthermore, invalid Transfer Encoding headers were found to be parsed as valid which could be leveraged for TE:CL smuggling attacks.","aliases":["CVE-2020-7670"],"modified":"2026-09-10T03:48:58.890885784Z","published":"2020-10-20T19:15:38Z","withdrawn":"2021-01-13T19:25:43Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2020-10-20T19:04:34Z","nvd_published_at":null,"cwe_ids":["CWE-444"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-7670"},{"type":"WEB","url":"https://github.com/ohler55/agoo/issues/88"},{"type":"WEB","url":"https://github.com/ohler55/agoo/commit/23d03535cf7b50d679a60a953a0cae9519a4a130"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-RUBY-AGOO-569137"}],"affected":[{"package":{"name":"agoo","ecosystem":"RubyGems","purl":"pkg:gem/agoo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"2.13.0"}]}],"versions":["0.9.0","0.9.1","1.0.0","1.1.0","1.1.1","1.1.2","1.2.0","1.2.1","1.2.2","2.0.0","2.0.2","2.0.3","2.0.4","2.0.5","2.1.0","2.1.1","2.1.3","2.10.0","2.11.0","2.11.1","2.11.2","2.11.3","2.11.4","2.11.5","2.11.6","2.11.7","2.12.0","2.12.1","2.12.2","2.12.3","2.13.0","2.2.0","2.2.1","2.2.2","2.3.0","2.4.0","2.5.0","2.5.1","2.5.2","2.5.3","2.5.4","2.5.5","2.5.6","2.5.7","2.6.0","2.6.1","2.7.0","2.8.0","2.8.1","2.8.2","2.8.3","2.8.4","2.9.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/10/GHSA-h385-52j6-9984/GHSA-h385-52j6-9984.json"}}],"schema_version":"1.9.0"}