Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-8852

Опубликовано: 12 мар. 2015
Источник: redhat
CVSS2: 5.8
EPSS Низкий

Описание

Varnish 3.x before 3.0.7, when used in certain stacked installations, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a header line terminated by a \r (carriage return) character in conjunction with multiple Content-Length headers in an HTTP request.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Software Collectionsrh-varnish4-varnishNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-113

EPSS

Процентиль: 78%
0.0109
Низкий

5.8 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 10 лет назад

Varnish 3.x before 3.0.7, when used in certain stacked installations, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a header line terminated by a \r (carriage return) character in conjunction with multiple Content-Length headers in an HTTP request.

CVSS3: 7.5
nvd
почти 10 лет назад

Varnish 3.x before 3.0.7, when used in certain stacked installations, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a header line terminated by a \r (carriage return) character in conjunction with multiple Content-Length headers in an HTTP request.

CVSS3: 7.5
debian
почти 10 лет назад

Varnish 3.x before 3.0.7, when used in certain stacked installations, ...

CVSS3: 7.5
github
больше 3 лет назад

Varnish 3.x before 3.0.7, when used in certain stacked installations, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a header line terminated by a \r (carriage return) character in conjunction with multiple Content-Length headers in an HTTP request.

EPSS

Процентиль: 78%
0.0109
Низкий

5.8 Medium

CVSS2