Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4w8v-46j6-77cf

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The HTTPS implementation in Google Chrome before 28.0.1500.71 does not ensure that headers are terminated by \r\n\r\n (carriage return, newline, carriage return, newline), which allows man-in-the-middle attackers to have an unspecified impact via vectors that trigger header truncation.

The HTTPS implementation in Google Chrome before 28.0.1500.71 does not ensure that headers are terminated by \r\n\r\n (carriage return, newline, carriage return, newline), which allows man-in-the-middle attackers to have an unspecified impact via vectors that trigger header truncation.

EPSS

Процентиль: 64%
0.0112
Низкий

Связанные уязвимости

ubuntu
около 13 лет назад

The HTTPS implementation in Google Chrome before 28.0.1500.71 does not ensure that headers are terminated by \r\n\r\n (carriage return, newline, carriage return, newline), which allows man-in-the-middle attackers to have an unspecified impact via vectors that trigger header truncation.

nvd
около 13 лет назад

The HTTPS implementation in Google Chrome before 28.0.1500.71 does not ensure that headers are terminated by \r\n\r\n (carriage return, newline, carriage return, newline), which allows man-in-the-middle attackers to have an unspecified impact via vectors that trigger header truncation.

debian
около 13 лет назад

The HTTPS implementation in Google Chrome before 28.0.1500.71 does not ...

EPSS

Процентиль: 64%
0.0112
Низкий