Vulnerability Details CVE-2020-11709
cpp-httplib through 0.5.8 does not filter \r\n in parameters passed into the set_redirect and set_header functions, which creates possibilities for CRLF injection and HTTP response splitting in some specific contexts.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 38.0%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2020-11709
-
cpe:2.3:a:cpp-httplib_project:cpp-httplib:-
-
cpe:2.3:a:cpp-httplib_project:cpp-httplib:0.2.0
-
cpe:2.3:a:cpp-httplib_project:cpp-httplib:0.2.1
-
cpe:2.3:a:cpp-httplib_project:cpp-httplib:0.2.2
-
cpe:2.3:a:cpp-httplib_project:cpp-httplib:0.2.3
-
cpe:2.3:a:cpp-httplib_project:cpp-httplib:0.2.4
-
cpe:2.3:a:cpp-httplib_project:cpp-httplib:0.2.5
-
cpe:2.3:a:cpp-httplib_project:cpp-httplib:0.2.6
-
cpe:2.3:a:cpp-httplib_project:cpp-httplib:0.3.0
-
cpe:2.3:a:cpp-httplib_project:cpp-httplib:0.3.1
-
cpe:2.3:a:cpp-httplib_project:cpp-httplib:0.3.2
-
cpe:2.3:a:cpp-httplib_project:cpp-httplib:0.3.3
-
cpe:2.3:a:cpp-httplib_project:cpp-httplib:0.4.0
-
cpe:2.3:a:cpp-httplib_project:cpp-httplib:0.4.1
-
cpe:2.3:a:cpp-httplib_project:cpp-httplib:0.4.2
-
cpe:2.3:a:cpp-httplib_project:cpp-httplib:0.5.0
-
cpe:2.3:a:cpp-httplib_project:cpp-httplib:0.5.1
-
cpe:2.3:a:cpp-httplib_project:cpp-httplib:0.5.2
-
cpe:2.3:a:cpp-httplib_project:cpp-httplib:0.5.3
-
cpe:2.3:a:cpp-httplib_project:cpp-httplib:0.5.4
-
cpe:2.3:a:cpp-httplib_project:cpp-httplib:0.5.5
-
cpe:2.3:a:cpp-httplib_project:cpp-httplib:0.5.6
-
cpe:2.3:a:cpp-httplib_project:cpp-httplib:0.5.7
-
cpe:2.3:a:cpp-httplib_project:cpp-httplib:0.5.8