HTTP Request Field Handling Vulnerability in Embedthis GoAhead and Appweb
CVE-2018-15504

7.5HIGH

Key Information:

Vendor

Embedthis

Vendor
CVE Published:
18 August 2018

What is CVE-2018-15504?

An issue has been identified in the handling of specific HTTP request fields within Embedthis GoAhead and Appweb. This vulnerability can result in a NULL pointer dereference, potentially causing server crashes when certain date fields, such as If-Modified-Since or If-Unmodified-Since, are manipulated incorrectly, especially with values representing months greater than 11. The affected versions prior to 4.0.1 for GoAhead and 7.0.2 for Appweb are particularly susceptible to this issue, highlighting a need for immediate patches to prevent service disruptions.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2018-15504 : HTTP Request Field Handling Vulnerability in Embedthis GoAhead and Appweb