McAfee Web Gateway 7.0 allows remote attackers to bypass the access configuration for the CONNECT method by providing an arbitrary allowed hostname in the Host HTTP header. NOTE: this issue might not be reproducible, because the researcher did not provide configuration details for the vulnerable system, and the observed behavior might be consistent with a configuration that was (perhaps inadvertently) designed to allow access based on Host HTTP headers
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 06 Aug 2024 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-16T19:41:57.659Z
Reserved: 2012-04-06T00:00:00Z
Link: CVE-2012-2212
Updated: 2024-08-06T19:26:08.994Z
Status : Deferred
Published: 2012-04-28T10:06:13.210
Modified: 2025-04-11T00:51:21.963
Link: CVE-2012-2212
No data.
OpenCVE Enrichment
No data.
Weaknesses