Server-Side Request Forgery Vulnerability in Recurly Client .NET Library

Server-Side Request Forgery Vulnerability in Recurly Client .NET Library

CVE-2017-0907 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

The Recurly Client .NET Library before 1.0.1, 1.1.10, 1.2.8, 1.3.2, 1.4.14, 1.5.3, 1.6.2, 1.7.1, 1.8.1 is vulnerable to a Server-Side Request Forgery vulnerability due to incorrect use of "Uri.EscapeUriString" that could result in compromise of API keys or other critical resources.

Learn more about our Cis Benchmark Audit For Server Software.