CVE-2021-20802: Medium severity cybozu remote service manager vulnerability
Published Oct 13, 2021
·Updated
HTTP header injection vulnerability in Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote attacker to alter the information stored in the product.
Affected Software
2 affected components
Cybozu Remote Service Manager=3.1.8
Cybozu Remote Service Manager=3.1.9
Event History
Oct 13, 2021
CVE Published
via MITRE·08:30 AM
Data Sourced
via MITRE·08:30 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this HTTP header injection vulnerability?
The vulnerability ID for this HTTP header injection vulnerability is CVE-2021-20802.
2
What is the severity of CVE-2021-20802?
The severity of CVE-2021-20802 is medium (5.3).
3
What software versions are affected by CVE-2021-20802?
Cybozu Remote Service versions 3.1.8 and 3.1.9 are affected by CVE-2021-20802.
4
How does CVE-2021-20802 work?
CVE-2021-20802 allows a remote attacker to alter the information stored in Cybozu Remote Service by injecting malicious headers in HTTP requests.
5
How can I fix the HTTP header injection vulnerability (CVE-2021-20802)?
To fix the HTTP header injection vulnerability, it is recommended to update Cybozu Remote Service to a version that includes the security patch.