CVE-2017-0907

CVE-2017-0907

Vendor Recurly
Product recurly-api-client .NET library
Weakness CWE-918 · SSRF
Published November 13, 2017
Last update September 16, 2024

CVSS base score

What the vulnerability does

01Description

The Recurly Client .NET Library before 1.0.1, 1.1.10, 1.2.8, 1.3.2, 1.4.14, 1.5.3, 1.6.2, 1.7.1, 1.8.1 is vulnerable to a Server-Side Request Forgery vulnerability due to incorrect use of "Uri.EscapeUriString" that could result in compromise of API keys or other critical resources.

Key dates

02Disclosure timeline

November 13, 2017 CVE published
September 16, 2024 Record updated

Related vulnerabilities

04Related CVE