CVE-2024-12973: Host Header Injection in Akinsoft's OctoCloud
Published Sep 2, 2025
·Updated
Origin Validation Error vulnerability in Akinsoft OctoCloud allows HTTP Response Splitting, CAPEC - 87 - Forceful Browsing.
This issue affects OctoCloud: from s1.09.01 before v1.11.01.
Affected Software
1 affected component
Akinsoft OctoCloud>=s1.09.01<v1.11.01
Event History
Sep 2, 2025
CVE Published
via MITRE·11:43 AM
Data Sourced
via MITRE·11:43 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-12973?
CVE-2024-12973 is rated as a high severity vulnerability due to its potential for HTTP Response Splitting attacks.
2
How do I fix CVE-2024-12973?
To fix CVE-2024-12973, upgrade Akinsoft OctoCloud to version 1.11.01 or later.
3
What versions of Akinsoft OctoCloud are affected by CVE-2024-12973?
Akinsoft OctoCloud versions from s1.09.01 to before 1.11.01 are affected by CVE-2024-12973.
4
What type of attack does CVE-2024-12973 enable?
CVE-2024-12973 allows for HTTP Response Splitting, which can lead to various security issues including forceful browsing.
5
Is CVE-2024-12973 an Origin Validation Error vulnerability?
Yes, CVE-2024-12973 is classified as an Origin Validation Error vulnerability.