Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-23936
HistoryFeb 16, 2023 - 6:15 p.m.

Crlf injection

2023-02-1618:15:00
PRIOn knowledge base
www.prio-n.com
11
undici
http/1.1
crlf injection
vulnerability
patched
version 5.19.1
sanitize headers

6.4 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

47.9%

Undici is an HTTP/1.1 client for Node.js. Starting with version 2.0.0 and prior to version 5.19.1, the undici library does not protect host HTTP header from CRLF injection vulnerabilities. This issue is patched in Undici v5.19.1. As a workaround, sanitize the headers.host string before passing to undici.