Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-11783

Опубликовано: 07 мар. 2019
Источник: ubuntu
Приоритет: medium
CVSS2: 5
CVSS3: 7.5

Описание

sslheaders plugin extracts information from the client certificate and sets headers in the request based on the configuration of the plugin. The plugin doesn't strip the headers from the request in some scenarios. This problem was discovered in versions 6.0.0 to 6.0.3, 7.0.0 to 7.1.5, and 8.0.0 to 8.0.1.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
cosmic

ignored

end of life
devel

DNE

disco

not-affected

8.0.2+ds-1ubuntu1
eoan

not-affected

8.0.2+ds-1ubuntu1
esm-apps/bionic

needs-triage

esm-apps/focal

not-affected

8.0.2+ds-1ubuntu1
esm-apps/jammy

not-affected

8.0.2+ds-1ubuntu1
esm-apps/noble

not-affected

8.0.2+ds-1ubuntu1
esm-apps/xenial

needs-triage

Показывать по

5 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
почти 7 лет назад

sslheaders plugin extracts information from the client certificate and sets headers in the request based on the configuration of the plugin. The plugin doesn't strip the headers from the request in some scenarios. This problem was discovered in versions 6.0.0 to 6.0.3, 7.0.0 to 7.1.5, and 8.0.0 to 8.0.1.

CVSS3: 7.5
debian
почти 7 лет назад

sslheaders plugin extracts information from the client certificate and ...

CVSS3: 7.5
github
больше 3 лет назад

sslheaders plugin extracts information from the client certificate and sets headers in the request based on the configuration of the plugin. The plugin doesn't strip the headers from the request in some scenarios. This problem was discovered in versions 6.0.0 to 6.0.3, 7.0.0 to 7.1.5, and 8.0.0 to 8.0.1.

5 Medium

CVSS2

7.5 High

CVSS3