Back

MEDIUM

vertx: Improper neutralization of CRLF sequences allows remote attackers to inject arbitrary HTTP response headers

Published Aug 14, 2018

Description

In Eclipse Vert.x version 3.0 to 3.5.1, the HttpServer response headers and HttpClient request headers do not filter carriage return and line feed characters from the header value. This allow unfiltered values to inject a new header in the client request or server response.

Affected products

Remediation

Red Hat statement

While the affected artifact is being shipped in Fuse 6.3 via camel-vertx component, the vulnerable code is not being used, therefore Fuse 6.3 is not affected.

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner eclipse
Published Aug 14, 2018
Updated Aug 5, 2024
Reserved Jun 18, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jun 13, 2018
ENISA EUVD
Assigner eclipse
Published Aug 14, 2018
Updated Aug 5, 2024
Exploited since n/a
EUVD-2018-0516 GHSA-6CW8-7J6C-HCCP