Description
A host header injection vulnerability in the HTTP handler component of Crafty Controller allows a remote, unauthenticated attacker to trigger a Denial of Service (DoS) condition via a modified host header
No analysis available yet.
Remediation
Vendor Solution
Upgrade to Crafty Controller 4.2.3 or higher OR block requests to the Crafty Controller HTTP port
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-16839 | A host header injection vulnerability in the HTTP handler component of Crafty Controller allows a remote, unauthenticated attacker to trigger a Denial of Service (DoS) condition via a modified host header |
References
| Link | Providers |
|---|---|
| https://gitlab.com/crafty-controller/crafty-4/-/issues/327 |
|
History
No history.
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2024-08-29T15:04:54.738Z
Reserved: 2024-01-30T09:30:40.948Z
Link: CVE-2024-1064
Updated: 2024-08-01T18:26:30.489Z
Status : Modified
Published: 2024-02-03T09:15:11.250
Modified: 2024-11-21T08:49:42.843
Link: CVE-2024-1064
No data.
OpenCVE Enrichment
No data.
EUVD