Security Advisory

CVE-2017-0907

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2017-11-13 17:00:00
Last updated 2024-09-16 23:00:52
Assigner hackerone
State PUBLISHED

Description

The Recurly Client .NET Library before 1.0.1, 1.1.10, 1.2.8, 1.3.2, 1.4.14, 1.5.3, 1.6.2, 1.7.1, 1.8.1 is vulnerable to a Server-Side Request Forgery vulnerability due to incorrect use of "Uri.EscapeUriString" that could result in compromise of API keys or other critical resources.