HTTP Response Splitting
Affecting openjdk-jre package, versions [1.7.0,1.7.0_261) || [1.8.0,1.8.0_251) || [11.0.0,11.0.7) || [14.0.0,14.0.1)
Report new vulnerabilities
Do your applications use this vulnerable package?
Test your applications
Overview
openjdk-jre is a free and open-source implementation of the Java Platform, Standard Edition (Java SE).
Affected versions of this package are vulnerable to HTTP Response Splitting. The HttpServer
implementation did not restrict the use of CR
and LF
characters in values for HTTP
headers, possibly allowing HTTP
response splitting attacks.
Remediation
Upgrade openjdk-jre
to version 7.0.261, 8.0.251, 11.0.7, 14.0.1 or higher.
References
CVSS Score
4.8
medium severity
-
Attack VectorNetwork
-
Attack ComplexityHigh
-
Privileges RequiredNone
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityLow
-
IntegrityLow
-
AvailabilityNone
- Credit
- Unknown
- CVE
- CVE-2020-2800
- CWE
- CWE-113
- Snyk ID
- SNYK-UPSTREAM-OPENJDKJRE-565799
- Disclosed
- 16 Apr, 2020
- Published
- 16 Apr, 2020