CVE-2018-12537
3Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackepss 2.5%
probabilidade de exploração
2.5%top 17% das CVEs
exploração observada
nãonenhuma fonte reporta
In Eclipse Vert.x version 3.0 to 3.5.1, the HttpServer response headers and HttpClient request headers do not filter carriage return and line feed characters from the header value. This allow unfiltered values to inject a new header in the client request or server response.
Produtos afetados
The Eclipse Foundation · Eclipse Vert.xReferências
https://access.redhat.com/errata/RHSA-2018:2371https://access.redhat.com/errata/RHSA-2018:3768https://bugs.eclipse.org/bugs/show_bug.cgi?id=536038https://bugzilla.redhat.com/show_bug.cgi?id=1591072https://github.com/eclipse/vert.x/commit/1bb6445226c39a95e7d07ce3caaf56828e8aab72https://github.com/eclipse/vert.x/issues/2470https://www.compass-security.com/fileadmin/Datein/Research/Advisories/CSNC-2018-021_vertx.txt