Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qh6h-825q-q4mx

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

Ansible Tower as shipped with Red Hat CloudForms Management Engine 5 is vulnerable to CRLF Injection. It was found that X-Forwarded-For header allows internal servers to deploy other systems (using callback).

Ansible Tower as shipped with Red Hat CloudForms Management Engine 5 is vulnerable to CRLF Injection. It was found that X-Forwarded-For header allows internal servers to deploy other systems (using callback).

EPSS

Процентиль: 35%
0.00144
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-93

Связанные уязвимости

CVSS3: 5.2
nvd
больше 7 лет назад

Ansible Tower as shipped with Red Hat CloudForms Management Engine 5 is vulnerable to CRLF Injection. It was found that X-Forwarded-For header allows internal servers to deploy other systems (using callback).

EPSS

Процентиль: 35%
0.00144
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-93