Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-1226

Опубликовано: 12 мар. 2024
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

The software does not neutralize or incorrectly neutralizes certain characters before the data is included in outgoing HTTP headers. The inclusion of invalidated data in an HTTP header allows an attacker to specify the full HTTP response represented by the browser. An attacker could control the response and craft attacks such as cross-site scripting and cache poisoning attacks.

EPSS

Процентиль: 31%
0.00118
Низкий

7.5 High

CVSS3

Дефекты

CWE-93

Связанные уязвимости

CVSS3: 7.5
github
почти 2 года назад

The software does not neutralize or incorrectly neutralizes certain characters before the data is included in outgoing HTTP headers. The inclusion of invalidated data in an HTTP header allows an attacker to specify the full HTTP response represented by the browser. An attacker could control the response and craft attacks such as cross-site scripting and cache poisoning attacks.

EPSS

Процентиль: 31%
0.00118
Низкий

7.5 High

CVSS3

Дефекты

CWE-93