Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:44551
HistoryDec 01, 2023 - 8:36 a.m.

CRLF Injection

2023-12-0108:36:31
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11
aiohttp
crlf injection
vulnerability
http version validation
request header
software

7.2 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

7.2 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

19.8%

aiohttp is vulnerable to CRLF Injection attack. The vulnerability arises due to improper HTTP version validation in aiohttp/client_reqrep.py. An attacker can preform CRLF injection if they have the ability to modify the HTTP version in the request header.

CPENameOperatorVersion
aiohttple3.9.0rc0
aiohttple3.9.0rc0

7.2 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

7.2 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

19.8%