Back to search
CVE-2018-12537
Published: Aug 14, 2018
Modified: Aug 5, 2024
PUBLISHED
Description
In Eclipse Vert.x version 3.0 to 3.5.1, the HttpServer response headers and HttpClient request headers do not filter carriage return and line feed characters from the header value. This allow unfiltered values to inject a new header in the client request or server response.
| Vendor | Product | Versions |
|---|---|---|
The Eclipse Foundation | Eclipse Vert.x | affected 3.0 - < unspecifiedaffected unspecified - <= 3.5.1 |
Weaknesses (CWE)
References
RHSA-2018:2371
vendor-advisory
x_refsource_REDHAT
https://github.com/eclipse/vert.x/issues/2470
x_refsource_CONFIRM
https://bugs.eclipse.org/bugs/show_bug.cgi?id=536038
x_refsource_CONFIRM
RHSA-2018:3768
vendor-advisory
x_refsource_REDHAT
https://bugzilla.redhat.com/show_bug.cgi?id=1591072
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now