SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-17513

An issue was discovered in Ratpack before 1.7.5.

HIGH 7.5EPSS 2.15%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (2.15%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

An issue was discovered in Ratpack before 1.7.5. Due to a misuse of the Netty library class DefaultHttpHeaders, there is no validation that headers lack HTTP control characters. Thus, if untrusted data is used to construct HTTP headers with Ratpack, HTTP Response Splitting can occur.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS
2.15% probability · 81th percentile
CISA KEV
Not listed
Weakness
CWE-74
Affected
ratpack project/ratpack
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.