HIGH
An issue was discovered in Ratpack before 1.7.5
Published Oct 18, 2019
7.5
HIGHCVSS 3.1
EPSS 2.15%
Description
An issue was discovered in Ratpack before 1.7.5. Due to a misuse of the Netty library class DefaultHttpHeaders, there is no validation that headers lack HTTP control characters. Thus, if untrusted data is used to construct HTTP headers with Ratpack, HTTP Response Splitting can occur.
Affected products
No data.
- < 1.7.5
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (8)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-0708 Advisory
- https://github.com/advisories/GHSA-mvqp-q37c-wf9j Advisory
- https://github.com/ratpack/ratpack/commit/c560a8d10cb8bdd7a526c1ca2e67c8f224ca23ae x_refsource_MISCPatch
- https://github.com/ratpack/ratpack/commit/efb910d38a96494256f36675ef0e5061097dd77d x_refsource_MISCPatch
- https://github.com/ratpack/ratpack/releases/tag/v1.7.5 x_refsource_CONFIRMRelease NotesThird Party Advisory
- https://github.com/ratpack/ratpack/security/advisories/GHSA-mvqp-q37c-wf9j x_refsource_CONFIRMThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-17513
- https://ratpack.io/versions/1.7.5 x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-0708 | Advisory | |
| https://github.com/advisories/GHSA-mvqp-q37c-wf9j | Advisory | |
| https://github.com/ratpack/ratpack/commit/c560a8d10cb8bdd7a526c1ca2e67c8f224ca23ae | x_refsource_MISCPatch | |
| https://github.com/ratpack/ratpack/commit/efb910d38a96494256f36675ef0e5061097dd77d | x_refsource_MISCPatch | |
| https://github.com/ratpack/ratpack/releases/tag/v1.7.5 | x_refsource_CONFIRMRelease NotesThird Party Advisory | |
| https://github.com/ratpack/ratpack/security/advisories/GHSA-mvqp-q37c-wf9j | x_refsource_CONFIRMThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-17513 | ||
| https://ratpack.io/versions/1.7.5 | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 18, 2019
Updated Aug 5, 2024
Reserved Oct 11, 2019
Link CVE-2019-17513
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2019-0708 GHSA-MVQP-Q37C-WF9J Assigner mitre
Published Oct 18, 2019
Updated Aug 5, 2024
Exploited since n/a
Link EUVD-2019-0708