Denial-of-Service Vulnerability in GoAhead Web Server by Embedthis
CVE-2019-5097
5.3MEDIUM
What is CVE-2019-5097?
A denial-of-service vulnerability has been identified in the processing of multipart/form-data requests within the GoAhead web server application. This issue can be exploited through specially crafted HTTP requests, potentially causing an infinite loop in the server's processing. Importantly, it does not require authentication and can be executed using both GET and POST requests, regardless of whether the requested resource exists on the server.
Affected Version(s)
EmbedThis EmbedThis GoAhead Web Server v5.0.1 EmbedThis GoAhead Web Server v4.1.1 EmbedThis GoAhead Web Server v3.6.5
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved