QID 983091
QID 983091: Java (maven) Security Update for io.vertx:vertx-core (GHSA-6cw8-7j6c-hccp)
In Eclipse Vert.x version 3.0 to 3.5.1, the HttpServer response headers and HttpClient request headers do not filter carriage return and line feed characters from the header value. This allow unfiltered values to inject a new header in the client request or server response.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-6cw8-7j6c-hccp for updates pertaining to this vulnerability.
Vendor References
- GHSA-6cw8-7j6c-hccp -
github.com/advisories/GHSA-6cw8-7j6c-hccp
CVEs related to QID 983091
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-6cw8-7j6c-hccp | io.vertx:vertx-core |
|