vertx: Improper neutralization of CRLF sequences allows remote attackers to inject arbitrary HTTP response headers
Published Aug 14, 2018
5.3
MEDIUMCVSS 3.0
EPSS 2.48%
Description
In Eclipse Vert.x version 3.0 to 3.5.1, the HttpServer response headers and HttpClient request headers do not filter carriage return and line feed characters from the header value. This allow unfiltered values to inject a new header in the client request or server response.
Affected products
-
- Version 3.0StatusaffectedConstraints<unspecified
- Version unspecifiedStatusaffectedConstraints<=3.5.1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| The Eclipse Foundation | Eclipse Vert.x | n/a |
|
No data.
Red Hat Fuse 7.2
vertx
Fixed · RHSA-2018:3768
Text-Only RHOAR
vertx
Fixed · RHSA-2018:2371
Red Hat JBoss Fuse 6
vertx
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Fuse 7.2 | vertx | Fixed | RHSA-2018:3768 |
| Text-Only RHOAR | vertx | Fixed | RHSA-2018:2371 |
| Red Hat JBoss Fuse 6 | vertx | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
While the affected artifact is being shipped in Fuse 6.3 via camel-vertx component, the vulnerable code is not being used, therefore Fuse 6.3 is not affected.
References (12)
- https://access.redhat.com/errata/RHSA-2018:2371 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3768 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2018-12537 Vendor Advisory
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=536038 x_refsource_CONFIRMIssue TrackingThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1591072 x_refsource_CONFIRMIssue TrackingThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-0516 Advisory
- https://github.com/advisories/GHSA-6cw8-7j6c-hccp Advisory
- https://github.com/eclipse/vert.x/commit/1bb6445226c39a95e7d07ce3caaf56828e8aab72 x_refsource_CONFIRMThird Party Advisory
- https://github.com/eclipse/vert.x/issues/2470 x_refsource_CONFIRMThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-12537
- https://www.compass-security.com/fileadmin/Datein/Research/Advisories/CSNC-2018-021_vertx.txt x_refsource_MISCThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2018-12537
Change history (0)
No recorded changes yet.