CVE-2019-17513
CVSS v3.1
7.5 (High)
CVSS v2.0
5 (Medium)
EPSS
0.14 % (50th)
Affected Products
1
Advisories
1
An issue was discovered in Ratpack before 1.7.5. Due to a misuse of the Netty library class DefaultHttpHeaders, there is no validation that headers lack HTTP control characters. Thus, if untrusted data is used to construct HTTP headers with Ratpack, HTTP Response Splitting can occur.
Weaknesses
- CWE-74
- Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
- CVE Status
- PUBLISHED
- CNA
- MITRE
- Published Date
-
2019-10-18 03:15:09
(4 years ago) - Updated Date
-
2020-08-24 17:37:01
(4 years ago)
Affected Products
Loading...
Loading...
Loading...
Configuration #1
|
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...