CVE-2020-29022: Host Header Injection allowing web cache poisoning attacks
Failure to Sanitize host header value on output in the GateManager Web server could allow an attacker to conduct web cache poisoning attacks. This issue affects Secomea GateManager all versions prior to 9.3
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-29022?
CVE-2020-29022 is a vulnerability that allows an attacker to conduct web cache poisoning attacks by exploiting the failure to sanitize the host header value on output in the GateManager Web server.
Which software versions are affected by CVE-2020-29022?
CVE-2020-29022 affects Secomea GateManager versions prior to 9.3.
How severe is CVE-2020-29022?
CVE-2020-29022 has a severity rating of 5.3, which is considered medium.
How can an attacker exploit CVE-2020-29022?
An attacker can exploit CVE-2020-29022 by manipulating the host header value to conduct web cache poisoning attacks.
Is there a fix for CVE-2020-29022?
Yes, Secomea has released a fix for CVE-2020-29022. It is recommended to update to GateManager version 9.3 or later to mitigate this vulnerability.