First published: Thu Mar 15 2018(Updated: )
In Apache Allura prior to 1.8.1, attackers may craft URLs that cause HTTP response splitting. If a victim goes to a maliciously crafted URL, unwanted results may occur including XSS or service denial for the victim's browsing session.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Allura | <=1.8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1319 is a vulnerability in Apache Allura prior to version 1.8.1 that allows attackers to craft URLs that cause HTTP response splitting.
CVE-2018-1319 has a severity rating of 6.1, which is considered medium.
CVE-2018-1319 affects Apache Allura versions up to and including 1.8.0.
The potential consequences of CVE-2018-1319 include XSS (cross-site scripting) attacks and denial of service for the victim's browsing session.
To fix CVE-2018-1319, users should upgrade to Apache Allura version 1.8.1 or later.