ZeroHour

CVE-2020-7611

PoC ×2
CVSS 3.1
9.8 critical
EPSS
2%p77
Published
()
Modified
Description

All versions of io.micronaut:micronaut-http-client before 1.2.11 and all versions from 1.3.0 before 1.3.2 are vulnerable to HTTP Request Header Injection due to not validating request headers passed to the client.

Vendors
objectcomputing
Products
micronaut
Weakness
CWE-444
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.