CVE-2017-0907
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
The Recurly Client .NET Library before 1.0.1, 1.1.10, 1.2.8, 1.3.2, 1.4.14, 1.5.3, 1.6.2, 1.7.1, 1.8.1 is vulnerable to a Server-Side Request Forgery vulnerability due to incorrect use of "Uri.EscapeUriString" that could result in compromise of API keys or other critical resources.
Affected (44)
Products: Recurly: Recurly Client .net
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.0.0.1 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.1.0 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.2.0 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.3.0 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.4.0 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.5.0 |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.6.0 |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.7.0 |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.8.0 |
References (6)
Source: support@hackerone.com
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
Timeline
No history available yet.