Description
Cloud Foundry routing-release, versions prior to 0.175.0, lacks sanitization for user-provided X-Forwarded-Proto headers. A remote user can set the X-Forwarded-Proto header in a request to potentially bypass an application requirement to only respond over secure connections.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-11829 | Cloud Foundry routing-release, versions prior to 0.175.0, lacks sanitization for user-provided X-Forwarded-Proto headers. A remote user can set the X-Forwarded-Proto header in a request to potentially bypass an application requirement to only respond over secure connections. |
References
| Link | Providers |
|---|---|
| https://www.cloudfoundry.org/blog/cve-2018-1193/ |
|
History
No history.
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2024-09-17T03:47:48.896Z
Reserved: 2017-12-06T00:00:00.000Z
Link: CVE-2018-1193
No data.
Status : Modified
Published: 2018-05-23T15:29:00.253
Modified: 2024-11-21T03:59:22.253
Link: CVE-2018-1193
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD