HTTP Response Splitting Vulnerability in Drogon Framework by Drogon
CVE-2023-26137

7.2HIGH

Key Information:

Vendor

Drogon

Vendor
CVE Published:
6 July 2023

What is CVE-2023-26137?

The Drogon Framework is susceptible to an HTTP Response Splitting vulnerability, which arises when untrusted user input is utilized to construct header values in the addHeader and addCookie functions. Attackers can exploit this vulnerability by injecting carriage return and line feed characters ('\r\n') into the HTTP response headers, thereby enabling them to introduce malicious content. This manipulation could lead to various attacks, including session hijacking and exploitation of web application behaviors.

Affected Version(s)

drogonframework/drogon 0

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alessio Della Libera - Snyk Research Team
.