CVE-2017-14063

Source
https://nvd.nist.gov/vuln/detail/CVE-2017-14063
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-14063.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2017-14063
Aliases
Published
2017-08-31T16:29:00Z
Modified
2024-10-12T02:32:38.215866Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

Async Http Client (aka async-http-client) before 2.0.35 can be tricked into connecting to a host different from the one extracted by java.net.URI if a '?' character occurs in a fragment identifier. Similar bugs were previously identified in cURL (CVE-2016-8624) and Oracle Java 8 java.net.URL.

References

Affected packages

Git / github.com/asynchttpclient/async-http-client

Affected ranges

Type
GIT
Repo
https://github.com/asynchttpclient/async-http-client
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

2.*

2.0.0-alpha1
2.0.0-alpha2
2.0.0-alpha3
2.0.0-alpha4
2.0.0-alpha5
2.0.0-alpha6
2.0.0-alpha7
2.0.0-alpha8

async-http-client-1.*

async-http-client-1.0.0
async-http-client-1.1.0
async-http-client-1.2.0
async-http-client-1.3.0
async-http-client-1.3.1
async-http-client-1.3.2
async-http-client-1.4.0
async-http-client-1.4.1
async-http-client-1.5.0
async-http-client-1.6.0
async-http-client-1.6.1
async-http-client-1.6.2
async-http-client-1.6.3
async-http-client-1.6.4
async-http-client-1.7.0
async-http-client-1.7.0-RC1
async-http-client-1.7.1
async-http-client-1.7.2
async-http-client-1.7.3
async-http-client-1.7.4
async-http-client-1.7.5

async-http-client-project-2.*

async-http-client-project-2.0.0
async-http-client-project-2.0.0-RC1
async-http-client-project-2.0.0-RC10
async-http-client-project-2.0.0-RC11
async-http-client-project-2.0.0-RC12
async-http-client-project-2.0.0-RC13
async-http-client-project-2.0.0-RC14
async-http-client-project-2.0.0-RC15
async-http-client-project-2.0.0-RC16
async-http-client-project-2.0.0-RC17
async-http-client-project-2.0.0-RC18
async-http-client-project-2.0.0-RC19
async-http-client-project-2.0.0-RC2
async-http-client-project-2.0.0-RC20
async-http-client-project-2.0.0-RC21
async-http-client-project-2.0.0-RC3
async-http-client-project-2.0.0-RC4
async-http-client-project-2.0.0-RC5
async-http-client-project-2.0.0-RC6
async-http-client-project-2.0.0-RC7
async-http-client-project-2.0.0-RC8
async-http-client-project-2.0.0-RC9
async-http-client-project-2.0.0-alpha10
async-http-client-project-2.0.0-alpha11
async-http-client-project-2.0.0-alpha12
async-http-client-project-2.0.0-alpha13
async-http-client-project-2.0.0-alpha14
async-http-client-project-2.0.0-alpha15
async-http-client-project-2.0.0-alpha16
async-http-client-project-2.0.0-alpha17
async-http-client-project-2.0.0-alpha18
async-http-client-project-2.0.0-alpha19
async-http-client-project-2.0.0-alpha20
async-http-client-project-2.0.0-alpha21
async-http-client-project-2.0.0-alpha22
async-http-client-project-2.0.0-alpha23
async-http-client-project-2.0.0-alpha24
async-http-client-project-2.0.0-alpha25
async-http-client-project-2.0.0-alpha26
async-http-client-project-2.0.0-alpha27
async-http-client-project-2.0.0-alpha9
async-http-client-project-2.0.1
async-http-client-project-2.0.10
async-http-client-project-2.0.11
async-http-client-project-2.0.12
async-http-client-project-2.0.13
async-http-client-project-2.0.14
async-http-client-project-2.0.15
async-http-client-project-2.0.16
async-http-client-project-2.0.17
async-http-client-project-2.0.18
async-http-client-project-2.0.19
async-http-client-project-2.0.2
async-http-client-project-2.0.20
async-http-client-project-2.0.21
async-http-client-project-2.0.22
async-http-client-project-2.0.23
async-http-client-project-2.0.24
async-http-client-project-2.0.25
async-http-client-project-2.0.26
async-http-client-project-2.0.27
async-http-client-project-2.0.28
async-http-client-project-2.0.29
async-http-client-project-2.0.3
async-http-client-project-2.0.30
async-http-client-project-2.0.31
async-http-client-project-2.0.32
async-http-client-project-2.0.33
async-http-client-project-2.0.34
async-http-client-project-2.0.4
async-http-client-project-2.0.5
async-http-client-project-2.0.6
async-http-client-project-2.0.7
async-http-client-project-2.0.8
async-http-client-project-2.0.9