An issue was discovered in Ratpack before 1.7.5. Due to a misuse of the Netty library class DefaultHttpHeaders, there is no validation that headers lack HTTP control characters. Thus, if untrusted data is used to construct HTTP headers with Ratpack, HTTP Response Splitting can occur.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2019-10-18T02:36:25
Updated: 2024-08-05T01:40:15.853Z
Reserved: 2019-10-11T00:00:00
Link: CVE-2019-17513
Vulnrichment
No data.
NVD
Status : Modified
Published: 2019-10-18T03:15:09.897
Modified: 2024-11-21T04:32:25.217
Link: CVE-2019-17513
Redhat
No data.