All versions of the package drogonframework/drogon are vulnerable to CRLF Injection when untrusted user input is used to set request headers in the addHeader function. An attacker can add the \r\n (carriage return line feeds) characters and inject additional headers in the request sent.
Metrics
Affected Vendors & Products
References
History
Tue, 19 Nov 2024 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
MITRE
Status: PUBLISHED
Assigner: snyk
Published: 2023-07-06T05:00:01.214Z
Updated: 2024-11-19T18:57:08.451Z
Reserved: 2023-02-20T10:28:48.926Z
Link: CVE-2023-26138
Vulnrichment
Updated: 2024-08-02T11:39:06.797Z
NVD
Status : Modified
Published: 2023-07-06T05:15:09.250
Modified: 2024-11-21T07:50:51.387
Link: CVE-2023-26138
Redhat
No data.