Lucene search

K
githubGitHub Advisory DatabaseGHSA-77HV-8796-8CCP
HistoryJul 23, 2018 - 7:51 p.m.

HTTP header injection in Plone and Zope2

2018-07-2319:51:50
GitHub Advisory Database
github.com
11

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:P/A:P

EPSS

0.012

Percentile

85.0%

ZPublisher.HTTPRequest._scrubHeader in Zope 2 before 2.13.19, as used in Plone before 4.3 beta 1, allows remote attackers to inject arbitrary HTTP headers via a linefeed (LF) character.

Affected configurations

Vulners
Node
ploneploneRange4.3a14.3a2
OR
ploneploneRange3.3.24.2.3
OR
zope2Range<2.13.19
VendorProductVersionCPE
ploneplone*cpe:2.3:a:plone:plone:*:*:*:*:*:*:*:*
*zope2*cpe:2.3:a:*:zope2:*:*:*:*:*:*:*:*

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:P/A:P

EPSS

0.012

Percentile

85.0%