CVE-2024-51451

Source
https://cve.org/CVERecord?id=CVE-2024-51451
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-51451.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-51451
Published
2026-02-04T22:15:56.830Z
Modified
2026-03-12T13:41:30.334255Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

IBM Concert 1.0.0 through 2.1.0 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking.

References

Affected packages

Git / github.com/ibm/concert

Affected ranges

Type
GIT
Repo
https://github.com/ibm/concert
Events
Database specific
{
    "versions": [
        {
            "introduced": "1.0.0"
        },
        {
            "fixed": "2.2.0"
        }
    ]
}

Affected versions

1.*
1.0.0
v1.*
v1.0.1
v1.0.2
v1.0.2.1
v1.0.2.2
v1.0.3
v1.0.4
v1.0.4.1
v1.0.5.1
v1.0.5.2
v1.0.5.4
v1.1.0
v2.*
v2.0.0.0
v2.0.0.1
v2.0.0.2
v2.1.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-51451.json"