VulnerabilityModified
CVE-2019-19240
The GoAhead WebsRedirect uses a static host buffer that has a limited length and can overflow.
MEDIUM 5.3EPSS 1.54%
Does this matter?
Lower severity and a low EPSS score (1.54%). Track it; it rarely justifies an emergency change on its own.
Description
Embedthis GoAhead before 5.0.1 mishandles redirected HTTP requests with a large Host header. The GoAhead WebsRedirect uses a static host buffer that has a limited length and can overflow. This can cause a copy of the Host header to fail, leaving that buffer uninitialized, which may leak uninitialized data in a response.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.54% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-787, CWE-908
- Affected
- embedthis/goahead
- Source
- cve@mitre.org
References
- https://github.com/embedthis/goahead/issues/289Exploit, Third Party Advisory
- https://github.com/embedthis/goahead/issues/290Third Party Advisory
- https://github.com/embedthis/goahead/releases/tag/v5.0.1Release Notes
- https://github.com/embedthis/goahead/issues/289Exploit, Third Party Advisory
- https://github.com/embedthis/goahead/issues/290Third Party Advisory
- https://github.com/embedthis/goahead/releases/tag/v5.0.1Release Notes
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.