Vulnerability Description
In Apache Allura prior to 1.8.1, attackers may craft URLs that cause HTTP response splitting. If a victim goes to a maliciously crafted URL, unwanted results may occur including XSS or service denial for the victim's browsing session.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Allura | <= 1.8.0 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/103434Third Party AdvisoryVDB Entry
- https://lists.apache.org/thread.html/22b74bc4002091157ec2bddf9fa3b7643ffaa77aa6c
- http://www.securityfocus.com/bid/103434Third Party AdvisoryVDB Entry
- https://lists.apache.org/thread.html/22b74bc4002091157ec2bddf9fa3b7643ffaa77aa6c
FAQ
What is CVE-2018-1319?
CVE-2018-1319 is a vulnerability with a CVSS score of 6.1 (MEDIUM). In Apache Allura prior to 1.8.1, attackers may craft URLs that cause HTTP response splitting. If a victim goes to a maliciously crafted URL, unwanted results may occur including XSS or service denial ...
How severe is CVE-2018-1319?
CVE-2018-1319 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-1319?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Allura.