Lucene search

K
cve[email protected]CVE-2022-35507
HistoryDec 04, 2022 - 7:15 p.m.

CVE-2022-35507

2022-12-0419:15:09
CWE-74
web.nvd.nist.gov
40
cve-2022-35507
proxmox
virtual environment
pve
mail gateway
pmg
crlf injection
dos
vulnerability
nvd

7.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H

6.8 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

52.6%

A response-header CRLF injection vulnerability in the Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) web interface allows a remote attacker to set cookies for a victim’s browser that are longer than the server expects, causing a client-side DoS. This affects Chromium-based browsers because they allow injection of response headers with %0d. This is fixed in pve-http-server 4.1-3.

Affected configurations

NVD
Node
proxmoxproxmox_mail_gatewayMatch-
OR
proxmoxpve_http_serverRange<4.1-3
OR
proxmoxvirtual_environmentMatch-

7.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H

6.8 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

52.6%

Related for CVE-2022-35507