CVE-2018-1319

Severity CVSS v4.0:
Pending analysis
Type:
CWE-74 Injection
Publication date:
15/03/2018
Last modified:
07/11/2023

Description

In Apache Allura prior to 1.8.1, attackers may craft URLs that cause HTTP response splitting. If a victim goes to a maliciously crafted URL, unwanted results may occur including XSS or service denial for the victim's browsing session.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:allura:*:*:*:*:*:*:*:* 1.8.0 (including)