6.5

CVE-2018-19791

Exploit

The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 does not correctly handle requests for byte sequences, allowing an attacker to amplify the response size by requesting the entire response body repeatedly, as demonstrated by an HTTP Range header value beginning with the "bytes=0-,0-" substring.

Data is provided by the National Vulnerability Database (NVD)
LitespeedtechOpenlitespeed Version < 1.5.0
LitespeedtechOpenlitespeed Version1.5.0 Update-
LitespeedtechOpenlitespeed Version1.5.0 Updaterc1
LitespeedtechOpenlitespeed Version1.5.0 Updaterc2
LitespeedtechOpenlitespeed Version1.5.0 Updaterc3
LitespeedtechOpenlitespeed Version1.5.0 Updaterc4
LitespeedtechOpenlitespeed Version1.5.0 Updaterc5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.29% 0.496
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.