CVE-2019-17513

Source
https://nvd.nist.gov/vuln/detail/CVE-2019-17513
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-17513.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-17513
Aliases
Published
2019-10-18T03:15:09Z
Modified
2024-05-14T06:59:37.020397Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

An issue was discovered in Ratpack before 1.7.5. Due to a misuse of the Netty library class DefaultHttpHeaders, there is no validation that headers lack HTTP control characters. Thus, if untrusted data is used to construct HTTP headers with Ratpack, HTTP Response Splitting can occur.

References

Affected packages

Git / github.com/ratpack/ratpack

Affected ranges

Type
GIT
Repo
https://github.com/ratpack/ratpack
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed

Affected versions

0.*

0.5.2
0.6.1

1.*

1.6.0-rc-1

Other

spring-boot-pr-3

v0.*

v0.9.0
v0.9.1
v0.9.10
v0.9.11
v0.9.12
v0.9.13
v0.9.14
v0.9.15
v0.9.16
v0.9.17
v0.9.18
v0.9.19
v0.9.2
v0.9.3
v0.9.4
v0.9.5
v0.9.6
v0.9.7
v0.9.8
v0.9.9

v1.*

v1.0.0
v1.0.0-rc-1
v1.0.0-rc-2
v1.0.0-rc-3
v1.1.0
v1.1.1
v1.2.0
v1.2.0-RC-1
v1.2.0-rc-2
v1.3.0
v1.3.0-rc-1
v1.3.0-rc-2
v1.3.1
v1.3.2
v1.3.3
v1.4.0
v1.4.0-rc-1
v1.4.0-rc-2
v1.4.0-rc-3
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.4.6
v1.5.0
v1.5.0-rc-1
v1.5.0-rc-2
v1.5.0-rc-3
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.6.0
v1.6.0-rc-2
v1.6.0-rc-3
v1.6.0-rc-4
v1.6.1
v1.7.0
v1.7.1
v1.7.2
v1.7.3
v1.7.4