In Eclipse Vert.x version 3.0 to 3.5.1, the HttpServer response headers and HttpClient request headers do not filter carriage return and line feed characters from the header value. This allow unfiltered values to inject a new header in the client request or server response.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: eclipse

Published: 2018-08-14T19:00:00

Updated: 2018-12-05T10:57:01

Reserved: 2018-06-18T00:00:00


Link: CVE-2018-12537

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2018-08-14T19:29:00.247

Modified: 2019-10-09T23:34:02.247


Link: CVE-2018-12537

JSON object: View

cve-icon Redhat Information

No data.