Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-26130
HistoryMay 30, 2023 - 5:15 a.m.

Crlf injection

2023-05-3005:15:00
PRIOn knowledge base
www.prio-n.com
6
crlf injection
http
package vulnerability
untrusted user input
content-type header
logical errors
misbehaviors
cve-2020-11709

8.2 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

74.5%

Versions of the package yhirose/cpp-httplib before 0.12.4 are vulnerable to CRLF Injection when untrusted user input is used to set the content-type header in the HTTP .Patch, .Post, .Put and .Delete requests. This can lead to logical errors and other misbehaviors.

Note: This issue is present due to an incomplete fix for CVE-2020-11709.

CPENameOperatorVersion
cpp-httpliblt0.12.4

8.2 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

74.5%