VulnerabilityModified
CVE-2019-17513
An issue was discovered in Ratpack before 1.7.5.
HIGH 7.5EPSS 2.15%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.15%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An issue was discovered in Ratpack before 1.7.5. Due to a misuse of the Netty library class DefaultHttpHeaders, there is no validation that headers lack HTTP control characters. Thus, if untrusted data is used to construct HTTP headers with Ratpack, HTTP Response Splitting can occur.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 2.15% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-74
- Affected
- ratpack project/ratpack
- Source
- cve@mitre.org
References
- https://github.com/ratpack/ratpack/commit/c560a8d10cb8bdd7a526c1ca2e67c8f224ca23aePatch
- https://github.com/ratpack/ratpack/commit/efb910d38a96494256f36675ef0e5061097dd77dPatch
- https://github.com/ratpack/ratpack/releases/tag/v1.7.5Release Notes, Third Party Advisory
- https://github.com/ratpack/ratpack/security/advisories/GHSA-mvqp-q37c-wf9jThird Party Advisory
- https://ratpack.io/versions/1.7.5Vendor Advisory
- https://github.com/ratpack/ratpack/commit/c560a8d10cb8bdd7a526c1ca2e67c8f224ca23aePatch
- https://github.com/ratpack/ratpack/commit/efb910d38a96494256f36675ef0e5061097dd77dPatch
- https://github.com/ratpack/ratpack/releases/tag/v1.7.5Release Notes, Third Party Advisory
- https://github.com/ratpack/ratpack/security/advisories/GHSA-mvqp-q37c-wf9jThird Party Advisory
- https://ratpack.io/versions/1.7.5Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.