Sploitus

CVE-2019-20800

No indexed exploits for CVE-2019-20800 yet

In Cherokee through 1.2.104, remote attackers can trigger an out-of-bounds write in cherokee_handler_cgi_add_env_pair in handler_cgi.c by sending many request headers, as demonstrated by a GET request with many "Host: 127.0.0.1" headers.

Affected products
Cherokee
Cherokee-project Cherokee
≤ 1.2.104
CVSS 3.1
9.8 CRITICAL
EPSS
2.1% (80th percentile)
Weakness
CWE-787
NVD status
Modified
Published
2020-05-17
CVE-2019-20800 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2019-20800 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2019-20800 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.