Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:13647
HistoryApr 16, 2019 - 3:25 a.m.

Carriage Return Line Feed (CRLF) Injection

2019-04-1603:25:10
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

0.004 Low

EPSS

Percentile

74.8%

urllib3 is vulnerable to CRLF injection. It is possible because it does not escape CRLF characters injected into the request parameter, allowing an attacker to manipulate the HTTP headers once the parameter is under control.

References