CVE-2023-23936

MEDIUM4.6EPSS 0.34%

CRLF Injection in Nodejs ‘undici’ via host

發布日:2023/2/16修改日:2024/12/16
也稱為:GHSA-5r9g-qh6m-jxffALPINE-CVE-2023-23936BIT-node-2023-23936BIT-node-min-2023-23936

描述

### Impact undici library does not protect `host` HTTP header from CRLF injection vulnerabilities. ### Patches This issue was patched in Undici v5.19.1. ### Workarounds Sanitize the `headers.host` string before passing to undici. ### References Reported at https://hackerone.com/reports/1820955. ### Credits Thank you to Zhipeng Zhang ([@timon8](https://hackerone.com/timon8)) for reporting this vulnerability.

受影響套件(5)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM4.6CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

參考連結(8)