Greenbone Security Assistant (GSA) before 7.0.3 and Greenbone OS (GOS) before 5.0.0 allow Host Header Injection.
References
Link | Resource |
---|---|
https://github.com/greenbone/gsa/pull/318 | Patch Third Party Advisory |
https://github.com/greenbone/gsa/releases/tag/v7.0.3 | Release Notes Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2021-06-21 08:15
Updated : 2021-06-24 18:14
NVD link : CVE-2018-25016
Mitre link : CVE-2018-25016
JSON object : View
CWE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Products Affected
greenbone
- greenbone_os
- greenbone_security_assistant