CVE-2018-12537
MEDIUM 5.3EPSS 2.5%
In Eclipse Vert.x version 3.0 to 3.5.1, the HttpServer response headers and HttpClient request headers do not filter carriage return and line feed characters from the header value. This allow unfiltered values to inject a new header in the client request or server response.
- CVSS v3.0
- 5.3 MEDIUM
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N - CVSS v2.0
- 5.0 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N - EPSS
- 2.48% chance of exploitation in the next 30 days, 83th percentile
- Published
- 2018-08-14
- Updated
- 2024-08-05
Proof-of-concept exploits (1)
- tafamace/CVE-2018-125370★ · 2018-11-19