6.5
CVE-2018-19791
- EPSS 1.24%
- Veröffentlicht 03.12.2018 06:29:00
- Zuletzt bearbeitet 21.11.2024 03:58:33
- Erkennungen
The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 does not correctly handle requests for byte sequences, allowing an attacker to amplify the response size by requesting the entire response body repeatedly, as demonstrated by an HTTP Range header value beginning with the "bytes=0-,0-" substring.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Litespeedtech ≫ Openlitespeed Version < 1.5.0
Litespeedtech ≫ Openlitespeed Version 1.5.0 Update -
Litespeedtech ≫ Openlitespeed Version 1.5.0 Update rc1
Litespeedtech ≫ Openlitespeed Version 1.5.0 Update rc2
Litespeedtech ≫ Openlitespeed Version 1.5.0 Update rc3
Litespeedtech ≫ Openlitespeed Version 1.5.0 Update rc4
Litespeedtech ≫ Openlitespeed Version 1.5.0 Update rc5
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.24% | 0.652 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.5 | 2.8 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
|
| NIST | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:N/I:N/A:P
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
https://github.com/litespeedtech/openlitespeed/issues/117