Lucene search

K
osvGoogleOSV:CVE-2018-1193
HistoryMay 23, 2018 - 3:29 p.m.

CVE-2018-1193

2018-05-2315:29:00
Google
osv.dev
4

AI Score

5.6

Confidence

High

EPSS

0.001

Percentile

50.8%

Cloud Foundry routing-release, versions prior to 0.175.0, lacks sanitization for user-provided X-Forwarded-Proto headers. A remote user can set the X-Forwarded-Proto header in a request to potentially bypass an application requirement to only respond over secure connections.

AI Score

5.6

Confidence

High

EPSS

0.001

Percentile

50.8%