First published: Wed Mar 14 2018(Updated: )
The Embedthis HTTP library, and Appweb versions before 7.0.3, have a logic flaw related to the authCondition function in http/httpLib.c. With a forged HTTP request, it is possible to bypass authentication for the form and digest login types.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Embedthis Appweb | <=7.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-8715 is a logic flaw vulnerability in the Embedthis HTTP library and Appweb versions before 7.0.3.
CVE-2018-8715 has a severity score of 8.1, which is considered high.
An attacker can exploit CVE-2018-8715 by crafting a forged HTTP request to bypass authentication for the form and digest login types.
The Embedthis Appweb versions before 7.0.3, specifically up to and inclusive of version 7.0.2, are affected by CVE-2018-8715.
Yes, the fix for CVE-2018-8715 is included in Appweb version 7.0.3.