spectator-ext-ipcservlet is vulnerable to Improper Input Validation
62
Medium Risk
Affected versions are vulnerable to HTTP header injection due to improper sanitization of carriage return (CR) or line feed (LF) characters in header values. An attacker could exploit this by injecting malicious headers or manipulating the response structure, potentially leading to security issues such as response splitting, cache poisoning, or cross-site scripting in downstream systems.
You are affected if you are using a version that falls within the vulnerable range.
spectator-ext-ipcservlet is vulnerable to Improper Input Validation in versions 0.74.0 - 1.8.12.
Upgrade the com.netflix.spectator:spectator-ext-ipcservlet library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant