Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-11783

Опубликовано: 07 мар. 2019
Источник: debian
EPSS Низкий

Описание

sslheaders plugin extracts information from the client certificate and sets headers in the request based on the configuration of the plugin. The plugin doesn't strip the headers from the request in some scenarios. This problem was discovered in versions 6.0.0 to 6.0.3, 7.0.0 to 7.1.5, and 8.0.0 to 8.0.1.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
trafficserverfixed8.0.2+ds-1package

Примечания

  • https://github.com/apache/trafficserver/pull/4701

  • https://www.openwall.com/lists/oss-security/2019/02/13/6

EPSS

Процентиль: 78%
0.01124
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 7 лет назад

sslheaders plugin extracts information from the client certificate and sets headers in the request based on the configuration of the plugin. The plugin doesn't strip the headers from the request in some scenarios. This problem was discovered in versions 6.0.0 to 6.0.3, 7.0.0 to 7.1.5, and 8.0.0 to 8.0.1.

CVSS3: 7.5
nvd
почти 7 лет назад

sslheaders plugin extracts information from the client certificate and sets headers in the request based on the configuration of the plugin. The plugin doesn't strip the headers from the request in some scenarios. This problem was discovered in versions 6.0.0 to 6.0.3, 7.0.0 to 7.1.5, and 8.0.0 to 8.0.1.

CVSS3: 7.5
github
больше 3 лет назад

sslheaders plugin extracts information from the client certificate and sets headers in the request based on the configuration of the plugin. The plugin doesn't strip the headers from the request in some scenarios. This problem was discovered in versions 6.0.0 to 6.0.3, 7.0.0 to 7.1.5, and 8.0.0 to 8.0.1.

EPSS

Процентиль: 78%
0.01124
Низкий