CVE

CVE-2021-38165

CVE-2021-38165

HTParse in Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data or HTTP headers.

Source: CVE-2021-38165

Exit mobile version