CVE-2018-1193
—CVSS 3.0
5.3 medium
EPSS
1%p64
Published
()
Modified
Description
Cloud Foundry routing-release, versions prior to 0.175.0, lacks sanitization for user-provided X-Forwarded-Proto headers. A remote user can set the X-Forwarded-Proto header in a request to potentially bypass an application requirement to only respond over secure connections.
- Vendors
- cloudfoundry
- Products
- cf-deployment, routing-release
- Vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.