CVE-2019-10797: Medium severity wso2 transport http vulnerability
Published Feb 19, 2020
·Updated
Netty in WSO2 transport-http before v6.3.1 is vulnerable to HTTP Response Splitting due to HTTP Header validation being disabled.
Affected Software
1 affected component
WSO2 transport-http<6.3.1
Remediation
Patch Available
Event History
Feb 19, 2020
CVE Published
via MITRE·06:14 PM
Data Sourced
via MITRE·06:14 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2019-10797?
CVE-2019-10797 is a vulnerability in Netty in WSO2 transport-http before v6.3.1 that allows for HTTP Response Splitting due to disabled HTTP Header validation.
2
What is the severity of CVE-2019-10797?
The severity of CVE-2019-10797 is medium with a CVSS score of 6.5.
3
How does CVE-2019-10797 affect WSO2 transport-http?
CVE-2019-10797 affects WSO2 transport-http versions up to and excluding v6.3.1.
4
What is HTTP Response Splitting?
HTTP Response Splitting is a vulnerability that allows an attacker to inject additional HTTP headers, which can lead to various attacks such as cache poisoning, cross-site scripting, and session hijacking.
5
How can I fix CVE-2019-10797?
To fix CVE-2019-10797, upgrade to WSO2 transport-http version 6.3.1 or later.