A host header injection vulnerability in the HTTP handler component of Crafty Controller allows a remote, unauthenticated attacker to trigger a Denial of Service (DoS) condition via a modified host header
Loading...
Loading...
Score 7.5 from GitHub Security Advisory (severity: HIGH) published 2024-02-03. NVD baseline CVSS 7.5; sources differ by 0.0.
A host header injection vulnerability in the HTTP handler component of Crafty Controller allows a remote, unauthenticated attacker to trigger a Denial of Service (DoS) condition via a modified host header
February 3, 2024
November 21, 2024
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
See which npm, PyPI, Go, and Maven packages are affected by CVE-2024-1064
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.