CVE-2019-16771
Severity CVSS v4.0:
Pending analysis
Type:
CWE-74
Injection
Publication date:
06/12/2019
Last modified:
16/12/2019
Description
Versions of Armeria 0.85.0 through and including 0.96.0 are vulnerable to HTTP response splitting, which allows remote attackers to inject arbitrary HTTP headers via CRLF sequences when unsanitized data is used to populate the headers of an HTTP response. This vulnerability has been patched in 0.97.0. Potential impacts of this vulnerability include cross-user defacement, cache poisoning, Cross-site scripting (XSS), and page hijacking.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:linecorp:armeria:*:*:*:*:*:*:*:* | 0.85.0 (including) | 0.97.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



