CVE-2019-19326
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Silverstripe CMS sites through 4.4.4 which have opted into HTTP Cache Headers on responses served by the framework's HTTP layer can be vulnerable to web cache poisoning. Through modifying the X-Original-Url and X-HTTP-Method-Override headers, responses with malicious HTTP headers can return unexpected responses to other consumers of this cached response. Most other headers associated with web cache poisoning are already disabled through request hostname forgery whitelists.
Los sitios de Silverstripe CMS versiones hasta 4.4.4 que han optado por Encabezados HTTP Cache en las respuestas atendidas por medio de la capa HTTP del framework pueden ser vulnerables al envenenamiento de la caché web. Mediante la modificación de los encabezados X-Original-Url y X-HTTP-Method-Override, las respuestas con encabezados HTTP maliciosos pueden devolver respuestas inesperadas a otros consumidores de esta respuesta almacenada en caché. La mayoría de los otros encabezados asociados con el envenenamiento de la caché web ya están deshabilitados por medio de las listas blancas de falsificación del nombre de host de la petición
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-11-27 CVE Reserved
- 2020-07-15 CVE Published
- 2023-03-31 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.silverstripe.org/download/security-releases/CVE-2019-19326 | 2020-07-23 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Silverstripe Search vendor "Silverstripe" | Silverstripe Search vendor "Silverstripe" for product "Silverstripe" | >= 3.0.0 < 3.7.5 Search vendor "Silverstripe" for product "Silverstripe" and version " >= 3.0.0 < 3.7.5" | - |
Affected
| ||||||
Silverstripe Search vendor "Silverstripe" | Silverstripe Search vendor "Silverstripe" for product "Silverstripe" | >= 4.0.0 < 4.4.7 Search vendor "Silverstripe" for product "Silverstripe" and version " >= 4.0.0 < 4.4.7" | - |
Affected
| ||||||
Silverstripe Search vendor "Silverstripe" | Silverstripe Search vendor "Silverstripe" for product "Silverstripe" | >= 4.5.0 < 4.5.4 Search vendor "Silverstripe" for product "Silverstripe" and version " >= 4.5.0 < 4.5.4" | - |
Affected
|