First published: Mon Jun 21 2021(Updated: )
Greenbone Security Assistant (GSA) before 7.0.3 and Greenbone OS (GOS) before 5.0.0 allow Host Header Injection.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Greenbone Greenbone Security Assistant | <7.0.3 | |
Greenbone Greenbone Os | <5.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this security issue is CVE-2018-25016.
The title of this vulnerability is 'Greenbone Security Assistant (GSA) before 7.0.3 and Greenbone OS (GOS) before 5.0.0 allow Host Header Injection.'
The severity rating for this vulnerability is critical with a score of 9.8.
This vulnerability affects Greenbone Security Assistant (GSA) versions before 7.0.3.
This vulnerability affects Greenbone OS (GOS) versions before 5.0.0.
Yes, a fix for this vulnerability is available in Greenbone Security Assistant (GSA) version 7.0.3 and Greenbone OS (GOS) version 5.0.0.
Host Header Injection is a vulnerability that allows an attacker to manipulate the Host header of a request, which can lead to various attacks such as cache poisoning, server-side request forgery, and server-side request smuggling.
The Common Weakness Enumeration (CWE) ID associated with this vulnerability is CWE-74.