Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-14063

Опубликовано: 28 авг. 2017
Источник: redhat
CVSS3: 5.3

Описание

Async Http Client (aka async-http-client) before 2.0.35 can be tricked into connecting to a host different from the one extracted by java.net.URI if a '?' character occurs in a fragment identifier. Similar bugs were previously identified in cURL (CVE-2016-8624) and Oracle Java 8 java.net.URL.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Fuse 6async-http-clientWill not fix
Red Hat JBoss Fuse Service Works 6async-http-clientWill not fix
Red Hat JBoss Fuse 7async-http-clientFixedRHSA-2018:266911.09.2018

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1487563async-http-client: Invalid URL parsing with '?'

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

Async Http Client (aka async-http-client) before 2.0.35 can be tricked into connecting to a host different from the one extracted by java.net.URI if a '?' character occurs in a fragment identifier. Similar bugs were previously identified in cURL (CVE-2016-8624) and Oracle Java 8 java.net.URL.

CVSS3: 7.5
nvd
больше 8 лет назад

Async Http Client (aka async-http-client) before 2.0.35 can be tricked into connecting to a host different from the one extracted by java.net.URI if a '?' character occurs in a fragment identifier. Similar bugs were previously identified in cURL (CVE-2016-8624) and Oracle Java 8 java.net.URL.

CVSS3: 7.5
debian
больше 8 лет назад

Async Http Client (aka async-http-client) before 2.0.35 can be tricked ...

CVSS3: 7.5
github
больше 7 лет назад

Improper Input Validation in async-http-client

5.3 Medium

CVSS3