CVE Database
/

CVE-2018-12537

Back to search

CVE-2018-12537

Published: Aug 14, 2018

Modified: Aug 5, 2024

PUBLISHED

Description

In Eclipse Vert.x version 3.0 to 3.5.1, the HttpServer response headers and HttpClient request headers do not filter carriage return and line feed characters from the header value. This allow unfiltered values to inject a new header in the client request or server response.

VendorProductVersions

The Eclipse Foundation

Eclipse Vert.x

affected
3.0 - < unspecified
affected
unspecified - <= 3.5.1

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now