Логотип exploitDog
bind:CVE-2019-19326
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-19326

Количество 2

Количество 2

nvd логотип

CVE-2019-19326

больше 5 лет назад

Silverstripe CMS sites through 4.4.4 which have opted into HTTP Cache Headers on responses served by the framework's HTTP layer can be vulnerable to web cache poisoning. Through modifying the X-Original-Url and X-HTTP-Method-Override headers, responses with malicious HTTP headers can return unexpected responses to other consumers of this cached response. Most other headers associated with web cache poisoning are already disabled through request hostname forgery whitelists.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-q9ff-3q93-fm8m

больше 3 лет назад

SilverStripe Web Cache Poisoning through HTTPRequestBuilder

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2019-19326

Silverstripe CMS sites through 4.4.4 which have opted into HTTP Cache Headers on responses served by the framework's HTTP layer can be vulnerable to web cache poisoning. Through modifying the X-Original-Url and X-HTTP-Method-Override headers, responses with malicious HTTP headers can return unexpected responses to other consumers of this cached response. Most other headers associated with web cache poisoning are already disabled through request hostname forgery whitelists.

CVSS3: 5.9
0%
Низкий
больше 5 лет назад
github логотип
GHSA-q9ff-3q93-fm8m

SilverStripe Web Cache Poisoning through HTTPRequestBuilder

CVSS3: 5.9
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу