← Back

CVE-2017-0907

nvd nist
Published: Nov 13, 2017Modified: May 13, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

The Recurly Client .NET Library before 1.0.1, 1.1.10, 1.2.8, 1.3.2, 1.4.14, 1.5.3, 1.6.2, 1.7.1, 1.8.1 is vulnerable to a Server-Side Request Forgery vulnerability due to incorrect use of "Uri.EscapeUriString" that could result in compromise of API keys or other critical resources.

Affected (44)

1 product
Recurly Client .net
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
Recurly
Version 1.0.0.1
Version 1.0.0.2
Version 1.0.0.3
Version 1.0.0.4
Version 1.0.0
Version 1.0.0 beta1
Version 1.0.0 beta2
Version 1.0.0 beta3
Version 1.0.0 rc1
Configuration B
8 vulnerable
Vulnerable SoftwareAffected Versions
Recurly
Version 1.1.0
Version 1.1.1
Version 1.1.4
Version 1.1.5
Version 1.1.6
Version 1.1.7
Version 1.1.8
Version 1.1.9
Configuration C
6 vulnerable
Vulnerable SoftwareAffected Versions
Recurly
Version 1.2.0
Version 1.2.1
Version 1.2.2
Version 1.2.5
Version 1.2.6
Version 1.2.7
Configuration D
2 vulnerable
Vulnerable SoftwareAffected Versions
Recurly
Version 1.3.0
Version 1.3.1
Configuration E
14 vulnerable
Configuration F
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 1.5.0
Configuration G
2 vulnerable
Vulnerable SoftwareAffected Versions
Recurly
Version 1.6.0
Version 1.6.1
Configuration H
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 1.7.0
Configuration I
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 1.8.0

References (6)

Source: support@hackerone.com
Vendor Advisory
Source: support@hackerone.com
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required

Timeline

No history available yet.