PT-2017-13228 · Curl+1 · Curl+1

Published

2017-08-31

·

Updated

2020-12-16

·

CVE-2017-14063

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Async Http Client versions prior to 2.0.35
Description The issue allows Async Http Client to be tricked into connecting to a host different from the one extracted by java.net.URI if a '?' character occurs in a fragment identifier. This is similar to previously identified bugs in cURL and Oracle Java 8 java.net.URL.
Recommendations For versions prior to 2.0.35, update to version 2.0.35 or later to resolve the issue.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-14063
GHSA-93JQ-624G-4P9P

Affected Products

Oracle Java
Curl