CVE-2019-20800 Information
Feb 14, 2021
cve
Description
In Cherokee through 1.2.104 remote attackers can trigger an out-of-bounds write in cherokee_handler_cgi_add_env_pair in handler_cgi.c by sending many request headers as demonstrated by a GET request with many \Host: 127.0.0.1\ headers.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://github.com/cherokee/webserver/issues/1224 https://logicaltrust.net/blog/2019/11/cherokee.html
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: