CVE-2018-25016: Critical severity greenbone security assistant vulnerability
Greenbone Security Assistant (GSA) before 7.0.3 and Greenbone OS (GOS) before 5.0.0 allow Host Header Injection.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is CVE-2018-25016.
What is the title of this vulnerability?
The title of this vulnerability is 'Greenbone Security Assistant (GSA) before 7.0.3 and Greenbone OS (GOS) before 5.0.0 allow Host Header Injection.'
What is the severity rating for this vulnerability?
The severity rating for this vulnerability is critical with a score of 9.8.
How does this vulnerability affect the Greenbone Security Assistant (GSA)?
This vulnerability affects Greenbone Security Assistant (GSA) versions before 7.0.3.
How does this vulnerability affect the Greenbone OS (GOS)?
This vulnerability affects Greenbone OS (GOS) versions before 5.0.0.
Is there a fix or patch available for this vulnerability?
Yes, a fix for this vulnerability is available in Greenbone Security Assistant (GSA) version 7.0.3 and Greenbone OS (GOS) version 5.0.0.
What is Host Header Injection?
Host Header Injection is a vulnerability that allows an attacker to manipulate the Host header of a request, which can lead to various attacks such as cache poisoning, server-side request forgery, and server-side request smuggling.
What is the Common Weakness Enumeration (CWE) ID associated with this vulnerability?
The Common Weakness Enumeration (CWE) ID associated with this vulnerability is CWE-74.