CVE-2019-17513
Summary
| CVE | CVE-2019-17513 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-10-18 03:15:00 UTC |
| Updated | 2020-08-24 17:37:00 UTC |
| Description | An issue was discovered in Ratpack before 1.7.5. Due to a misuse of the Netty library class DefaultHttpHeaders, there is no validation that headers lack HTTP control characters. Thus, if untrusted data is used to construct HTTP headers with Ratpack, HTTP Response Splitting can occur. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Enable HTTP header validation · ratpack/ratpack@efb910d · GitHub |
MISC |
github.com |
Patch |
| CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') · Advisory · ratpack/ratpack · GitHub |
CONFIRM |
github.com |
Third Party Advisory |
| Add test for response header validation · ratpack/ratpack@c560a8d · GitHub |
MISC |
github.com |
Patch |
| Release v1.7.5 · ratpack/ratpack · GitHub |
CONFIRM |
github.com |
Release Notes, Third Party Advisory |
| Ratpack: Lean & powerful HTTP apps for the JVM |
MISC |
ratpack.io |
Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 980974 Java (maven) Security Update for io.ratpack:ratpack-core (GHSA-mvqp-q37c-wf9j)