A host header injection vulnerability in the HTTP handler component of Crafty Controller allows a remote, unauthenticated attacker to trigger a Denial of Service (DoS) condition via a modified host header
Fixes

Solution

Upgrade to Crafty Controller 4.2.3 or higher OR block requests to the Crafty Controller HTTP port


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2024-08-29T15:04:54.738Z

Reserved: 2024-01-30T09:30:40.948Z

Link: CVE-2024-1064

cve-icon Vulnrichment

Updated: 2024-08-01T18:26:30.489Z

cve-icon NVD

Status : Modified

Published: 2024-02-03T09:15:11.250

Modified: 2024-11-21T08:49:42.843

Link: CVE-2024-1064

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.