HTTP Header Injection Affecting zope2 package, versions [2.12,2.13.19)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
1.17% (86th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-ZOPE2-40106
  • published21 Nov 2012
  • disclosed21 Nov 2012
  • creditUnknown

Introduced: 21 Nov 2012

CVE-2012-5486  (opens in a new tab)
CWE-74  (opens in a new tab)

Overview

zope2 is a Zope2 application server / web framework ZPublisher.HTTPRequest._scrubHeader in Zope 2 before 2.13.19, as used in Plone before 4.3 beta 1, allows remote attackers to inject arbitrary HTTP headers via a linefeed (LF) character.

CVSS Scores

version 3.1