Versions of Armeria 0.85.0 through and including 0.96.0 are vulnerable to HTTP response splitting, which allows remote attackers to inject arbitrary HTTP headers via CRLF sequences when unsanitized data is used to populate the headers of an HTTP response. This vulnerability has been patched in 0.97.0. Potential impacts of this vulnerability include cross-user defacement, cache poisoning, Cross-site scripting (XSS), and page hijacking.
Advisories
Source ID Title
EUVD EUVD EUVD-2019-0769 Versions of Armeria 0.85.0 through and including 0.96.0 are vulnerable to HTTP response splitting, which allows remote attackers to inject arbitrary HTTP headers via CRLF sequences when unsanitized data is used to populate the headers of an HTTP response. This vulnerability has been patched in 0.97.0. Potential impacts of this vulnerability include cross-user defacement, cache poisoning, Cross-site scripting (XSS), and page hijacking.
Github GHSA Github GHSA GHSA-24r8-fm9r-cpj2 Low severity vulnerability that affects com.linecorp.armeria:armeria
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-05T01:24:48.270Z

Reserved: 2019-09-24T00:00:00

Link: CVE-2019-16771

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-12-06T19:15:10.787

Modified: 2024-11-21T04:31:09.460

Link: CVE-2019-16771

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.