Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-113 (HTTP头部中CRLF序列转义处理不恰当(HTTP响应分割)) — Vulnerability Class 55

55 vulnerabilities classified as CWE-113 (HTTP头部中CRLF序列转义处理不恰当(HTTP响应分割)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2023-26137 Drogon 环境问题漏洞 — drogonframework/drogon 7.2 High2023-07-06
CVE-2023-34472 AMI MegaRAC 安全漏洞 — MegaRAC_SPx 5.7 Medium2023-07-05
CVE-2023-0508 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') in GitLab — GitLab 3.1 Low2023-06-07
CVE-2023-32708 HTTP Response Splitting via the ‘rest’ SPL Command — Splunk Enterprise 7.2 High2023-06-01
CVE-2022-42472 Fortinet FortiOS 注入漏洞 — FortiProxy 4.0 Medium2023-02-16
CVE-2019-25101 OnShift TurboGears HTTP Header controllers.py response splitting — TurboGears 6.3 Medium2023-02-04
CVE-2022-37436 Apache HTTP Server: mod_proxy prior to 2.4.55 allows a backend to trigger HTTP response splitting — Apache HTTP Server 7.5 -2023-01-17
CVE-2022-42471 Fortinet FortiWeb 注入漏洞 — FortiWeb 5.3 Medium2023-01-03
CVE-2022-20772 多款Cisco产品注入漏洞 — Cisco Secure Email 4.7 Medium2022-11-03
CVE-2022-3215 swift-nio-http2 注入漏洞 — SwiftNIO 5.3 -2022-09-28
CVE-2022-37953 WorkstationST - Response Splitting in AM Gateway Challenge-Response — WorkstationST 4.7 Medium2022-08-25
CVE-2021-40336 HTTP Response Splitting in Hitachi Energy’s MSM Product — MSM 5.0 Medium2022-07-25
CVE-2021-0268 Junos OS: J-Web has an Improper Neutralization of CRLF Sequences in its HTTP Headers which allows an attacker to carry out multiple types of attacks. — Junos OS 8.8 High2021-04-22
CVE-2020-3117 Cisco Web Security Appliance and Cisco Content Security Management Appliance HTTP Header Injection Vulnerability — Cisco Web Security Appliance (WSA) 4.7 -2020-09-23
CVE-2020-10753 Red Hat Ceph 注入漏洞 — Red Hat Ceph Storage 5.4 Medium2020-06-26
CVE-2020-5249 HTTP Response Splitting (Early Hints) in Puma — Puma 6.5 Medium2020-03-02
CVE-2020-5247 HTTP Response Splitting in Puma — Puma 6.5 Medium2020-02-28
CVE-2020-5216 Limited header injection when using dynamic overrides with user input in RubyGems secure_headers — secure_headers 4.4 Medium2020-01-23
CVE-2019-16771 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') in Armeria — Armeria 4.8 Medium2019-12-06
CVE-2019-15259 Cisco Unified Contact Center Express HTTP Response Splitting Vulnerability — Cisco Unified Contact Center Express 4.7 -2019-10-02
CVE-2018-13814 Siemens SIMATIC Panels和SIMATIC WinCC 代码注入漏洞 — SIMATIC HMI Comfort Panels 4" - 22", SIMATIC HMI Comfort Outdoor Panels 7" & 15", SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F, KTP900 und KTP900F, SIMATIC WinCC Runtime Advanced, SIMATIC WinCC Runtime Professional, SIMATIC WinCC (TIA Portal), SIMATIC HMI Classic Devices (TP/MP/OP/MP Mobile Panel) 9.1 -2018-12-13
CVE-2017-7528 Red Hat CloudForms Management Engine 安全漏洞 — Ansible Tower 7.4 -2018-08-22
CVE-2018-1067 Red Hat Undertow 安全漏洞 — undertow 8.2 -2018-05-21
CVE-2017-12308 多款Cisco产品Cisco Small Business Managed Switches software 安全漏洞 — Cisco Small Business 300 and 500 Series Managed Switches 6.1 -2018-01-18
CVE-2017-12309 Cisco Email Security Appliance 安全漏洞 — Cisco Email Security Appliance 5.8 -2017-11-16

Vulnerabilities classified as CWE-113 (HTTP头部中CRLF序列转义处理不恰当(HTTP响应分割)) represent 55 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.