Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rqgr-h8g8-4p6w

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

CRLF injection vulnerability in Bugzilla before 3.2.9, 3.4.x before 3.4.9, 3.6.x before 3.6.3, and 4.0.x before 4.0rc1, when Server Push is enabled in a web browser, allows remote attackers to inject arbitrary HTTP headers and content, and conduct HTTP response splitting attacks, via a crafted URL.

CRLF injection vulnerability in Bugzilla before 3.2.9, 3.4.x before 3.4.9, 3.6.x before 3.6.3, and 4.0.x before 4.0rc1, when Server Push is enabled in a web browser, allows remote attackers to inject arbitrary HTTP headers and content, and conduct HTTP response splitting attacks, via a crafted URL.

EPSS

Процентиль: 72%
0.00733
Низкий

Дефекты

CWE-94

Связанные уязвимости

ubuntu
около 15 лет назад

CRLF injection vulnerability in Bugzilla before 3.2.9, 3.4.x before 3.4.9, 3.6.x before 3.6.3, and 4.0.x before 4.0rc1, when Server Push is enabled in a web browser, allows remote attackers to inject arbitrary HTTP headers and content, and conduct HTTP response splitting attacks, via a crafted URL.

nvd
около 15 лет назад

CRLF injection vulnerability in Bugzilla before 3.2.9, 3.4.x before 3.4.9, 3.6.x before 3.6.3, and 4.0.x before 4.0rc1, when Server Push is enabled in a web browser, allows remote attackers to inject arbitrary HTTP headers and content, and conduct HTTP response splitting attacks, via a crafted URL.

debian
около 15 лет назад

CRLF injection vulnerability in Bugzilla before 3.2.9, 3.4.x before 3. ...

EPSS

Процентиль: 72%
0.00733
Низкий

Дефекты

CWE-94