6.5
CVSSv3

CVE-2018-19791

Published: 03/12/2018 Updated: 05/02/2019
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

The server in LiteSpeed OpenLiteSpeed prior to 1.5.0 RC6 does not correctly handle requests for byte sequences, allowing an malicious user to amplify the response size by requesting the entire response body repeatedly, as demonstrated by an HTTP Range header value beginning with the "bytes=0-,0-" substring.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

litespeedtech openlitespeed 1.5.0

litespeedtech openlitespeed