All versions of the package ithewei/libhv are vulnerable to CRLF Injection when untrusted user input is used to set request headers. An attacker can add the \r\n (carriage return line feeds) characters and inject additional headers in the request sent.
References
Link | Resource |
---|---|
https://gist.github.com/dellalibera/65d136066fdd5ea4dddaadaa9b0ba90e | Exploit Third Party Advisory |
https://security.snyk.io/vuln/SNYK-UNMANAGED-ITHEWEILIBHV-5730769 | Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: snyk
Published: 2023-09-29T05:00:03.203Z
Updated: 2023-09-29T05:00:03.203Z
Reserved: 2023-02-20T10:28:48.929Z
Link: CVE-2023-26148
JSON object: View
NVD Information
Status : Modified
Published: 2023-09-29T05:15:46.693
Modified: 2023-11-07T04:09:28.547
Link: CVE-2023-26148
JSON object: View
Redhat Information
No data.