First published: Wed Sep 14 2022(Updated: )
Project Wonder WebObjects 1.0 through 5.4.3 is vulnerable to Arbitrary HTTP Header injection and URL- or Header-based XSS reflection in all web-server adaptor interfaces.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple WebObjects | >=1.0<=5.4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-37724 is considered a moderate severity vulnerability due to its potential for arbitrary HTTP header injection and XSS reflection.
To mitigate CVE-2022-37724, ensure that you validate and sanitize all user input in your web applications.
CVE-2022-37724 affects Apple WebObjects versions from 1.0 through 5.4.3.
CVE-2022-37724 makes systems vulnerable to arbitrary HTTP header injection attacks and URL- or header-based XSS reflection.
As of now, there is no officially released patch for CVE-2022-37724, so users should take immediate mitigation steps.