Записи asynchttpclient project
4 опубликованных записей вендора asynchttpclient project.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 75 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-20 Improper Input Validation1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-287 Improper Authentication1
- CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
4 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
36Наблюдать | CVE-2024-53990Эксплойта нет | AsyncHttpClient (AHC) library's `CookieStore` replaces explicitly defined `Cookie`sasynchttpclient · async-http-client · CWE-287 | Критическая9,2 | — | 0,6 % | 2 дек. 2024 г. |
31Наблюдать | CVE-2017-14063Эксплойта нет | Async Http Client (aka async-http-client) before 2.0.35 can be tricked into connecting to a host different from the one extracted by java.neasynchttpclient project · async-http-client · CWE-20 | Высокая7,5 | — | 3,0 % | 31 авг. 2017 г. |
30Наблюдать | CVE-2023-0040Эксплойта нет | Versions of Async HTTP Client prior to 1.13.2 are vulnerable to a form of targeted request manipulation called CRLF injection.asynchttpclient project · async-http-client · CWE-93 | Высокая7,5 | — | 0,5 % | 18 янв. 2023 г. |
29Наблюдать | CVE-2026-45300Эксплойта нет | async-http-client: Cookie header not stripped on cross-origin redirectasynchttpclient project · async-http-client · CWE-200 | Высокая7,4 | — | 0,5 % | 5 июн. 2026 г. |
- CVE-2024-5399036Наблюдать
AsyncHttpClient (AHC) library's `CookieStore` replaces explicitly defined `Cookie`s
КритическаяCVSS 9,2Эксплойта нетEPSS 1 %asynchttpclient · async-http-client2 дек. 2024 г.
- CVE-2017-1406331Наблюдать
Async Http Client (aka async-http-client) before 2.0.35 can be tricked into connecting to a host different from the one extracted by java.ne
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %asynchttpclient project · async-http-client31 авг. 2017 г.
- CVE-2023-004030Наблюдать
Versions of Async HTTP Client prior to 1.13.2 are vulnerable to a form of targeted request manipulation called CRLF injection.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %asynchttpclient project · async-http-client18 янв. 2023 г.
- CVE-2026-4530029Наблюдать
async-http-client: Cookie header not stripped on cross-origin redirect
ВысокаяCVSS 7,4Эксплойта нетEPSS 0 %asynchttpclient project · async-http-client5 июн. 2026 г.