All versions of io.micronaut:micronaut-http-client before 1.2.11 and all versions from 1.3.0 before 1.3.2 are vulnerable to HTTP Request Header Injection due to not validating request headers passed to the client.
[
{
"source": "https://github.com/micronaut-projects/micronaut-core/commit/9d1eff5c8df1d6cda1fe00ef046729b2a6abe7f1",
"target": {
"function": "NettyHttpHeaders",
"file": "http-netty/src/main/java/io/micronaut/http/netty/NettyHttpHeaders.java"
},
"deprecated": false,
"signature_version": "v1",
"id": "CVE-2020-7611-1bdd4467",
"signature_type": "Function",
"digest": {
"length": 119.0,
"function_hash": "279585357239160518281699105977565984920"
}
},
{
"source": "https://github.com/micronaut-projects/micronaut-core/commit/9d1eff5c8df1d6cda1fe00ef046729b2a6abe7f1",
"target": {
"file": "http-netty/src/main/java/io/micronaut/http/netty/NettyHttpHeaders.java"
},
"deprecated": false,
"signature_version": "v1",
"id": "CVE-2020-7611-c391728b",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"3288462943823054163738607323452904498",
"253714978496155313953035315991965338851",
"61570352787045959113304840899923945643",
"108640851695436842458951814569846236982"
]
}
}
]