Описание
All versions of io.micronaut:micronaut-http-client before 1.2.11 and all versions from 1.3.0 before 1.3.2 are vulnerable to HTTP Request Header Injection due to not validating request headers passed to the client.
Ссылки
- https://github.com/micronaut-projects/micronaut-core/commit/9d1eff5c8df1d6cda1fe00ef046729b2a6abe7f1Patch
- ExploitPatchThird Party Advisory
- ExploitThird Party Advisory
- https://github.com/micronaut-projects/micronaut-core/commit/9d1eff5c8df1d6cda1fe00ef046729b2a6abe7f1Patch
- ExploitPatchThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.2.11 (исключая)Версия от 1.3.0 (включая) до 1.3.2 (исключая)
Одно из
cpe:2.3:a:objectcomputing:micronaut:*:*:*:*:*:*:*:*
cpe:2.3:a:objectcomputing:micronaut:*:*:*:*:*:*:*:*
EPSS
Процентиль: 65%
0.005
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-444
Связанные уязвимости
CVSS3: 9.8
github
почти 6 лет назад
Micronaut's HTTP client is vulnerable to HTTP Request Header Injection
EPSS
Процентиль: 65%
0.005
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-444