Exploit maturity not defined.
The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade apache/kvrocks
to version 2.11.1-rc1 or higher.
Affected versions of this package are vulnerable to HTTP Request Smuggling when interpreting a RESP
request in Connection::ExecuteCommands()
, which accepts Host:
and POST
request types. An attacker can perform unauthorized database operations by sending specially crafted HTTP requests that are misinterpreted as valid RESP commands, if another compromise has already been performed that allows them to send messages to the affected service.