Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fcg7-7g94-695r

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

In Apache Allura prior to 1.8.1, attackers may craft URLs that cause HTTP response splitting. If a victim goes to a maliciously crafted URL, unwanted results may occur including XSS or service denial for the victim's browsing session.

In Apache Allura prior to 1.8.1, attackers may craft URLs that cause HTTP response splitting. If a victim goes to a maliciously crafted URL, unwanted results may occur including XSS or service denial for the victim's browsing session.

EPSS

Процентиль: 73%
0.00752
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 6.1
nvd
почти 8 лет назад

In Apache Allura prior to 1.8.1, attackers may craft URLs that cause HTTP response splitting. If a victim goes to a maliciously crafted URL, unwanted results may occur including XSS or service denial for the victim's browsing session.

EPSS

Процентиль: 73%
0.00752
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-74