5.8
CVSSv2

CVE-2019-10751

Published: 23/08/2019 Updated: 02/09/2019
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

All versions of the HTTPie package prior to version 1.0.3 are vulnerable to Open Redirect that allows an malicious user to write an arbitrary file with supplied filename and content to the current directory, by redirecting a request from HTTP to a crafted URL pointing to a server in his or hers control.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

httpie httpie

Vendor Advisories

Debian Bug report logs - #940058 httpie: CVE-2019-10751 Package: src:httpie; Maintainer for src:httpie is Bartosz Fenski <fenio@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 11 Sep 2019 20:03:01 UTC Severity: grave Tags: security, upstream Found in version httpie/098-2 Reply or ...