PoC Index

CVE-2018-12537

MEDIUM 5.3EPSS 2.5%

In Eclipse Vert.x version 3.0 to 3.5.1, the HttpServer response headers and HttpClient request headers do not filter carriage return and line feed characters from the header value. This allow unfiltered values to inject a new header in the client request or server response.

CVSS v3.0
5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS v2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS
2.48% chance of exploitation in the next 30 days, 83th percentile
Published
2018-08-14
Updated
2024-08-05

Proof-of-concept exploits (1)

References

Related