CVE-2017-14063
HIGHasync-http-client < 2.0.35 - Server-Side Request Forgery via Fragment Identifier
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2017-14063. PoCs published by dawetmaster, andikahilmy.
AI-analyzed exploit summary This repository contains the source code of the async-http-client library, which is vulnerable to CVE-2017-14063, but does not include any exploit code or proof-of-concept. It appears to be a snapshot of the vulnerable version of the library.
Description
Async Http Client (aka async-http-client) before 2.0.35 can be tricked into connecting to a host different from the one extracted by java.net.URI if a '?' character occurs in a fragment identifier. Similar bugs were previously identified in cURL (CVE-2016-8624) and Oracle Java 8 java.net.URL.
Exploits (2)
This repository contains the source code of the async-http-client library, which is vulnerable to CVE-2017-14063, but does not include any exploit code or proof-of-concept. It appears to be a snapshot of the vulnerable version of the library.
This repository contains a vulnerable version of the async-http-client library, specifically targeting CVE-2017-14063. The codebase includes the full implementation of the library, which can be used to demonstrate the vulnerability in a controlled environment.
References (28)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N