Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:13270
HistoryJan 28, 2019 - 2:45 a.m.

CRLF Injection

2019-01-2802:45:24
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
16

EPSS

0.001

Percentile

45.0%

pypiserver is vulnerable to CRLF injection. A remote attacker is able to inject newline characters %0d%0a into the server response and create arbitrary HTTP headers or perform cross-site scripting attacks. This is due to unescaped values being passed from a client and used directly for redirects.

EPSS

0.001

Percentile

45.0%