MEDIUM
Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') in Armeria
Published Dec 6, 2019
6.5
MEDIUMCVSS 3.1
EPSS 0.98%
Description
Versions of Armeria 0.85.0 through and including 0.96.0 are vulnerable to HTTP response splitting, which allows remote attackers to inject arbitrary HTTP headers via CRLF sequences when unsanitized data is used to populate the headers of an HTTP response. This vulnerability has been patched in 0.97.0. Potential impacts of this vulnerability include cross-user defacement, cache poisoning, Cross-site scripting (XSS), and page hijacking.
Affected products
-
- Version < 0.97.0StatusaffectedConstraints<0.97.0
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://github.com/advisories/GHSA-24r8-fm9r-cpj2 Advisory
- https://github.com/line/armeria/commit/b597f7a865a527a84ee3d6937075cfbb4470ed20 x_refsource_MISCPatchVendor Advisory
- https://github.com/line/armeria/security/advisories/GHSA-24r8-fm9r-cpj2
- https://github.com/line/armeria/security/advisories/GHSA-35fr-h7jr-hh86 x_refsource_CONFIRMMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-16771
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-24r8-fm9r-cpj2 | Advisory | |
| https://github.com/line/armeria/commit/b597f7a865a527a84ee3d6937075cfbb4470ed20 | x_refsource_MISCPatchVendor Advisory | |
| https://github.com/line/armeria/security/advisories/GHSA-24r8-fm9r-cpj2 | ||
| https://github.com/line/armeria/security/advisories/GHSA-35fr-h7jr-hh86 | x_refsource_CONFIRMMailing ListThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-16771 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Dec 6, 2019
Updated Aug 5, 2024
Reserved Sep 24, 2019
Link CVE-2019-16771
CISA Vulnrichment
GHSA-24R8-FM9R-CPJ2 Updated n/a