Vulnerabilities
Vulnerable Software
Apache:  >> Heron  >> 0.13.6  Security Vulnerabilities
Heron versions <= 0.20.4-incubating allows CRLF log injection because of the lack of escaping in the log statements. Please update to version 0.20.5-incubating which addresses this issue.
CVSS Score
9.8
EPSS Score
0.002
Published
2022-10-24
When accessing the heron-ui webpage, people can modify the file paths outside of the current container to access any file on the host. Example woule be modifying the parameter path= to go to the directory you would like to view. i.e. ..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd.
CVSS Score
7.5
EPSS Score
0.022
Published
2019-03-21


Contact Us

Shodan ® - All rights reserved