PT-2023-20526 · Unknown · Ithewei/Libhv

Alessio Della Libera

·

Publicado

2023-09-28

·

Atualizado

2023-10-02

·

CVE-2023-26148

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions ithewei/libhv versions all
Description The issue affects the ithewei/libhv package, where untrusted user input used to set request headers can lead to CRLF Injection. An attacker can inject additional headers into the request by adding carriage return line feeds (r ) characters.
Recommendations For all versions, consider restricting the use of untrusted user input in setting request headers until a patch is available. As a temporary workaround, validate and sanitize all user input to prevent the injection of malicious characters, such as r .

Exploit

Correção

Special Elements Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-26148

Produtos afetados

Ithewei/Libhv