Versions of Armeria 0.85.0 through and including 0.96.0 are vulnerable to HTTP response splitting, which allows remote attackers to inject arbitrary HTTP headers via CRLF sequences when unsanitized data is used to populate the headers of an HTTP response. This vulnerability has been patched in 0.97.0. Potential impacts of this vulnerability include cross-user defacement, cache poisoning, Cross-site scripting (XSS), and page hijacking.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: GitHub_M

Published: 2019-12-06T19:00:20

Updated: 2019-12-11T14:46:09

Reserved: 2019-09-24T00:00:00


Link: CVE-2019-16771

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2019-12-06T19:15:10.787

Modified: 2019-12-16T14:19:27.753


Link: CVE-2019-16771

JSON object: View

cve-icon Redhat Information

No data.