Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:4983
HistoryAug 31, 2017 - 5:28 a.m.

Malicious Host Redirect

2017-08-3105:28:37
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14

0.004 Low

EPSS

Percentile

74.6%

async-http-client is vulnerable to malicious host redirects. The library interprets the ? character in a URL as the beginning of a query or an ending of a path, allowing a malicious user to cause the application to connect to a malicious host.

CPENameOperatorVersion
ahc/clientle2.0.34
ahc/clientle2.0.24

References

0.004 Low

EPSS

Percentile

74.6%