Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 6

Количество 6

redhat логотип

CVE-2019-18802

больше 6 лет назад

An issue was discovered in Envoy 1.12.0. An untrusted remote client may send an HTTP header (such as Host) with whitespace after the header content. Envoy will treat "header-value " as a different string from "header-value" so for example with the Host header "example.com " one could bypass "example.com" matchers.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2019-18802

больше 6 лет назад

An issue was discovered in Envoy 1.12.0. An untrusted remote client may send an HTTP header (such as Host) with whitespace after the header content. Envoy will treat "header-value " as a different string from "header-value" so for example with the Host header "example.com " one could bypass "example.com" matchers.

CVSS3: 9.8
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:0341-1

больше 5 лет назад

Security update for nghttp2

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2020:0379-1

больше 6 лет назад

Security update for nghttp2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:0722-1

больше 6 лет назад

Security update for nghttp2

EPSS: Низкий
github логотип

GHSA-fx83-72pw-c56f

больше 4 лет назад

An issue was discovered in Envoy 1.12.0. An untrusted remote client may send an HTTP header (such as Host) with whitespace after the header content. Envoy will treat "header-value " as a different string from "header-value" so for example with the Host header "example.com " one could bypass "example.com" matchers.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2019-18802

An issue was discovered in Envoy 1.12.0. An untrusted remote client may send an HTTP header (such as Host) with whitespace after the header content. Envoy will treat "header-value " as a different string from "header-value" so for example with the Host header "example.com " one could bypass "example.com" matchers.

CVSS3: 7.5
2%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-18802

An issue was discovered in Envoy 1.12.0. An untrusted remote client may send an HTTP header (such as Host) with whitespace after the header content. Envoy will treat "header-value " as a different string from "header-value" so for example with the Host header "example.com " one could bypass "example.com" matchers.

CVSS3: 9.8
2%
Низкий
больше 6 лет назад
suse-cvrf логотип
openSUSE-SU-2021:0341-1

Security update for nghttp2

2%
Низкий
больше 5 лет назад
suse-cvrf логотип
openSUSE-SU-2020:0379-1

Security update for nghttp2

2%
Низкий
больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2020:0722-1

Security update for nghttp2

2%
Низкий
больше 6 лет назад
github логотип
GHSA-fx83-72pw-c56f

An issue was discovered in Envoy 1.12.0. An untrusted remote client may send an HTTP header (such as Host) with whitespace after the header content. Envoy will treat "header-value " as a different string from "header-value" so for example with the Host header "example.com " one could bypass "example.com" matchers.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад

Уязвимостей на страницу