-
Bug
-
Resolution: Unresolved
-
Medium
-
None
-
8.13.10, 9.4.0, 9.4.9
-
8.13
-
3
-
Severity 2 - Major
-
3
-
We have found during testing that by sending a fake header with a domain name (supplying as a suffix (i.e. attack.eu)) into the Host header field, the web server processes the input to send the request to an attacker-controlled host that resides at the supplied domain, and not to an internal virtual host that resides on the web server.
Affected versions:
- 8.13.10
Earlier fixed versions:
- 7.13.16
- 8.5.7
- 8.9.2
- 8.10.1
- 8.11.0
- is cloned from
-
JRASERVER-71275 IDOR Disclosure of Private Project Titles - CVE-2020-14174
- Closed
- followed by
-
SEF-15650 Loading...
- mentioned in
-
Page Loading...