CVE-2017-14063
Last modified
CVE-2017-14063 is a vulnerability of currently unknown severity. Async Http Client (aka async-http-client) before 2.0.35 can be tricked into connecting to a host different from the one extracted by java.net.URI if a '?' character occurs in a fragment identifier. Similar bugs were previously identified in cURL (CVE-2016-8624) and Oracle Java 8 java.net.URL.. EPSS estimates a 3.05% chance of exploitation in the next 30 days.
Description
Async Http Client (aka async-http-client) before 2.0.35 can be tricked into connecting to a host different from the one extracted by java.net.URI if a '?' character occurs in a fragment identifier. Similar bugs were previously identified in cURL (CVE-2016-8624) and Oracle Java 8 java.net.URL.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Asynchttpclient Project | Async-Http-Client | < 2.0.35 |
References
- http://openwall.com/lists/oss-security/2017/08/31/4Mailing List, Patch, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2669Third Party Advisory
- https://github.com/AsyncHttpClient/async-http-client/issues/1455Issue Tracking, Patch, Third Party Advisory
- http://openwall.com/lists/oss-security/2017/08/31/4Mailing List, Patch, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2669Third Party Advisory
- https://github.com/AsyncHttpClient/async-http-client/issues/1455Issue Tracking, Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-14063?
How severe is CVE-2017-14063?
How do I fix CVE-2017-14063?
Are you affected by CVE-2017-14063?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
