Vulnerability Description
Facebook Proxygen before 2015-11-09 mismanages HTTPMessage.request state, which allows remote attackers to conduct hijacking attacks and bypass ACL checks.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Proxygen Project | Proxygen | <= 0.32.0 |
Related Weaknesses (CWE)
References
- https://groups.google.com/forum/#%21topic/facebook-proxygen/K8wCXbW4ihs
- https://groups.google.com/forum/#%21topic/facebook-proxygen/K8wCXbW4ihs
FAQ
What is CVE-2015-7265?
CVE-2015-7265 is a vulnerability with a CVSS score of 7.5 (HIGH). Facebook Proxygen before 2015-11-09 mismanages HTTPMessage.request state, which allows remote attackers to conduct hijacking attacks and bypass ACL checks.
How severe is CVE-2015-7265?
CVE-2015-7265 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-7265?
Check the references section above for vendor advisories and patch information. Affected products include: Proxygen Project Proxygen.