asynchttpclient project kayıtları
asynchttpclient project üreticisine ait 4 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %75
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-20 Improper Input Validation1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-287 Improper Authentication1
- CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
4 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
36İzleyin | CVE-2024-53990İstismar yok | AsyncHttpClient (AHC) library's `CookieStore` replaces explicitly defined `Cookie`sasynchttpclient · async-http-client · CWE-287 | Kritik9,2 | — | %0,6 | 2 Ara 2024 |
31İzleyin | CVE-2017-14063İstismar yok | Async Http Client (aka async-http-client) before 2.0.35 can be tricked into connecting to a host different from the one extracted by java.neasynchttpclient project · async-http-client · CWE-20 | Yüksek7,5 | — | %3,0 | 31 Ağu 2017 |
30İzleyin | CVE-2023-0040İstismar yok | Versions of Async HTTP Client prior to 1.13.2 are vulnerable to a form of targeted request manipulation called CRLF injection.asynchttpclient project · async-http-client · CWE-93 | Yüksek7,5 | — | %0,5 | 18 Oca 2023 |
29İzleyin | CVE-2026-45300İstismar yok | async-http-client: Cookie header not stripped on cross-origin redirectasynchttpclient project · async-http-client · CWE-200 | Yüksek7,4 | — | %0,5 | 5 Haz 2026 |
- CVE-2024-5399036İzleyin
AsyncHttpClient (AHC) library's `CookieStore` replaces explicitly defined `Cookie`s
KritikCVSS 9,2İstismar yokEPSS %1asynchttpclient · async-http-client2 Ara 2024
- CVE-2017-1406331İzleyin
Async Http Client (aka async-http-client) before 2.0.35 can be tricked into connecting to a host different from the one extracted by java.ne
YüksekCVSS 7,5İstismar yokEPSS %3asynchttpclient project · async-http-client31 Ağu 2017
- CVE-2023-004030İzleyin
Versions of Async HTTP Client prior to 1.13.2 are vulnerable to a form of targeted request manipulation called CRLF injection.
YüksekCVSS 7,5İstismar yokEPSS %1asynchttpclient project · async-http-client18 Oca 2023
- CVE-2026-4530029İzleyin
async-http-client: Cookie header not stripped on cross-origin redirect
YüksekCVSS 7,4İstismar yokEPSS %0asynchttpclient project · async-http-client5 Haz 2026