CVE-2018-12537 Vulnerability Details

  /     /     /  

CVE-2018-12537 Metadata Quick Info

CVE Published: 14/08/2018 | CVE Updated: 05/08/2024 | CVE Year: 2018
Source: eclipse | Vendor: The Eclipse Foundation | Product: Eclipse Vert.x
Status : PUBLISHED

CVE-2018-12537 Description

In Eclipse Vert.x version 3.0 to 3.5.1, the HttpServer response headers and HttpClient request headers do not filter carriage return and line feed characters from the header value. This allow unfiltered values to inject a new header in the client request or server response.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-93
CWE Name: CWE-93: Improper Neutralization of CRLF Sequences ( CRLF Injection )
Source: The Eclipse Foundation

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).