CVE-2017-14063 is a vulnerability in Async Http Client (versions prior to 2.0.35) that allows an attacker to redirect connections to an unintended host by manipulating the fragment identifier with a '?' character. This high-severity vulnerability (CVSS 7.5) has a network attack vector and low complexity, potentially leading to high integrity impact without requiring user interaction. While no active exploitation, public exploit code, or significant community discussion has been observed, the flaw could enable various attacks such as bypassing security controls or facilitating phishing.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.0.35CPE matchmatch criteria | cpe:2.3:a:asynchttpclient_project:async-http-client:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.