CVE-2020-7611

All versions of io.micronaut:micronaut-http-client before 1.2.11 and all versions from 1.3.0 before 1.3.2 are vulnerable to HTTP Request Header Injection due to not validating request headers passed to the client.
Configurations

Configuration 1

cpe:2.3:a:objectcomputing:micronaut:*:*:*:*:*:*:*:*
cpe:2.3:a:objectcomputing:micronaut:*:*:*:*:*:*:*:*

Information

Published : 2020-03-30 10:15

Updated : 2020-04-02 02:37


NVD link : CVE-2020-7611

Mitre link : CVE-2020-7611

Products Affected
No products.
CWE
CWE-444

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')