Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-12537

Опубликовано: 13 июн. 2018
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

In Eclipse Vert.x version 3.0 to 3.5.1, the HttpServer response headers and HttpClient request headers do not filter carriage return and line feed characters from the header value. This allow unfiltered values to inject a new header in the client request or server response.

Отчет

While the affected artifact is being shipped in Fuse 6.3 via camel-vertx component, the vulnerable code is not being used, therefore Fuse 6.3 is not affected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Fuse 6vertxNot affected
Red Hat OpenShift Application RuntimesvertxAffected
Red Hat Fuse 7.2vertxFixedRHSA-2018:376804.12.2018
Text-Only RHOARFixedRHSA-2018:237109.08.2018

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-113
https://bugzilla.redhat.com/show_bug.cgi?id=1591072vertx: Improper neutralization of CRLF sequences allows remote attackers to inject arbitrary HTTP response headers

EPSS

Процентиль: 78%
0.01089
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
больше 7 лет назад

In Eclipse Vert.x version 3.0 to 3.5.1, the HttpServer response headers and HttpClient request headers do not filter carriage return and line feed characters from the header value. This allow unfiltered values to inject a new header in the client request or server response.

github
больше 7 лет назад

Moderate severity vulnerability that affects io.vertx:vertx-core

EPSS

Процентиль: 78%
0.01089
Низкий

5.3 Medium

CVSS3