Description
A host header injection vulnerability in the HTTP handler component of Crafty Controller allows a remote, unauthenticated attacker to trigger a Denial of Service (DoS) condition via a modified host header
Published: 2024-02-03
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Upgrade to Crafty Controller 4.2.3 or higher OR block requests to the Crafty Controller HTTP port

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-16839 A host header injection vulnerability in the HTTP handler component of Crafty Controller allows a remote, unauthenticated attacker to trigger a Denial of Service (DoS) condition via a modified host header
History

No history.

Subscriptions

Craftycontrol Crafty Controller
cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2024-08-29T15:04:54.738Z

Reserved: 2024-01-30T09:30:40.948Z

Link: CVE-2024-1064

cve-icon Vulnrichment

Updated: 2024-08-01T18:26:30.489Z

cve-icon NVD

Status : Modified

Published: 2024-02-03T09:15:11.250

Modified: 2024-11-21T08:49:42.843

Link: CVE-2024-1064

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses