MEDIUM6.5
GHSA-rvpc-w57p-q95f
HTTP Response Splitting in WSO2 transport-http
Quick fix
GHSA-rvpc-w57p-q95f — org.wso2.transport.http:org.wso2.transport.http.netty: upgrade to the fixed version with the command below.
# pom.xml: bump <version>6.3.1</version> for org.wso2.transport.http:org.wso2.transport.http.nettyDetails
Netty in WSO2 transport-http before v6.3.1 is vulnerable to HTTP Response Splitting due to HTTP Header validation being disabled.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.wso2.transport.http:org.wso2.transport.http.netty
Introduced in:
0Fixed in: 6.3.1Fix
# pom.xml: bump <version>6.3.1</version> for org.wso2.transport.http:org.wso2.transport.http.netty