CVE-2020-6858

Severity CVSS v4.0:
Pending analysis
Type:
CWE-74 Injection
Publication date:
12/03/2020
Last modified:
17/03/2020

Description

Hotels Styx through 1.0.0.beta8 allows HTTP response splitting due to CRLF Injection. This is exploitable if untrusted user input can appear in a response header.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hotels:styx:*:*:*:*:*:*:*:* 0.7.10 (including)
cpe:2.3:a:hotels:styx:1.0.0:beta1:*:*:*:*:*:*
cpe:2.3:a:hotels:styx:1.0.0:beta2:*:*:*:*:*:*
cpe:2.3:a:hotels:styx:1.0.0:beta3:*:*:*:*:*:*
cpe:2.3:a:hotels:styx:1.0.0:beta4:*:*:*:*:*:*
cpe:2.3:a:hotels:styx:1.0.0:beta5:*:*:*:*:*:*
cpe:2.3:a:hotels:styx:1.0.0:beta6:*:*:*:*:*:*
cpe:2.3:a:hotels:styx:1.0.0:beta7:*:*:*:*:*:*
cpe:2.3:a:hotels:styx:1.0.0:beta9:*:*:*:*:*:*