Vulnerabilities
Vulnerable Software
Async Http Client (aka async-http-client) before 2.0.35 can be tricked into connecting to a host different from the one extracted by java.net.URI if a '?' character occurs in a fragment identifier. Similar bugs were previously identified in cURL (CVE-2016-8624) and Oracle Java 8 java.net.URL.
CVSS Score
7.5
EPSS Score
0.011
Published
2017-08-31


Contact Us

Shodan ® - All rights reserved