CRLF injection vulnerability in the web framework in Cisco Web Security Appliance (WSA) 7.7 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct redirection attacks via a crafted URL, aka Bug ID CSCuj61002.
| Software | From | Fixed in |
|---|---|---|
| cisco / web_security_virtual_appliance | 7.1.1 | 7.1.1.x |
| cisco / web_security_virtual_appliance | 7.5.0 | 7.5.0.x |
| cisco / web_security_virtual_appliance | 7.1.3 | 7.1.3.x |
| cisco / web_security_virtual_appliance | 7.1.4 | 7.1.4.x |
| cisco / web_security_virtual_appliance | - | 7.7.x |
| cisco / web_security_virtual_appliance | 7.1.0 | 7.1.0.x |
| cisco / web_security_virtual_appliance | 7.1.2 | 7.1.2.x |
| cisco / web_security_virtual_appliance | 7.5.1 | 7.5.1.x |