CVE-2018-21245: Critical severity apsis pound vulnerability
Published Jun 15, 2020
·Updated
Pound before 2.8 allows HTTP request smuggling, a related issue to CVE-2016-10711.
Affected Software
1 affected component
APSIS Pound<2.8
Event History
Jun 15, 2020
CVE Published
via MITRE·04:50 PM
Data Sourced
via MITRE·04:50 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-21245?
CVE-2018-21245 is classified as a medium severity vulnerability related to HTTP request smuggling.
2
How do I fix CVE-2018-21245?
To mitigate CVE-2018-21245, upgrade Pound to version 2.8 or later.
3
What are the implications of CVE-2018-21245?
The implications of CVE-2018-21245 include potential HTTP request smuggling attacks that can compromise application security.
4
Who is affected by CVE-2018-21245?
CVE-2018-21245 affects users of Pound versions prior to 2.8.
5
What type of attacks can exploit CVE-2018-21245?
CVE-2018-21245 can be exploited through malformed HTTP requests leading to request smuggling issues.