Lucene search

K
nvd[email protected]NVD:CVE-2023-26130
HistoryMay 30, 2023 - 5:15 a.m.

CVE-2023-26130

2023-05-3005:15:10
CWE-93
CWE-74
web.nvd.nist.gov
1
vulnerability
yhirose/cpp-httplib
crlf injection
http requests
logical errors
incomplete fix

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

8.2 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

74.5%

Versions of the package yhirose/cpp-httplib before 0.12.4 are vulnerable to CRLF Injection when untrusted user input is used to set the content-type header in the HTTP .Patch, .Post, .Put and .Delete requests. This can lead to logical errors and other misbehaviors.

Note: This issue is present due to an incomplete fix for CVE-2020-11709.

Affected configurations

NVD
Node
cpp-httplib_projectcpp-httplibRange<0.12.4

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

8.2 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

74.5%