CVE-2023-40518: High severity openlitespeed vulnerability
Published Aug 14, 2023
·Updated
LiteSpeed OpenLiteSpeed before 1.7.18 does not strictly validate HTTP request headers.
Affected Software
1 affected component
Litespeedtech Openlitespeed<1.7.18
Event History
Aug 14, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-40518.
2
What is the severity rating of CVE-2023-40518?
CVE-2023-40518 has a severity rating of 7.5 (high).
3
What is affected by CVE-2023-40518?
LiteSpeed OpenLiteSpeed versions up to 1.7.18 are affected by CVE-2023-40518.
4
What is the impact of CVE-2023-40518?
CVE-2023-40518 allows attackers to bypass HTTP request header validation, potentially leading to various security vulnerabilities.
5
How can I fix CVE-2023-40518?
To fix CVE-2023-40518, upgrade to LiteSpeed OpenLiteSpeed version 1.7.18 or later.