CRLF Injection Vulnerability in Drogon Framework
CVE-2023-26138

5.4MEDIUM

Key Information:

Vendor

Drogon

Vendor
CVE Published:
6 July 2023

What is CVE-2023-26138?

All versions of the Drogon Framework are susceptible to CRLF Injection vulnerabilities. This occurs when untrusted user input is used to set request headers within the addHeader function. An attacker can exploit this flaw by injecting carriage return and line feed characters ( ) into the request, allowing them to add unauthorized headers to the HTTP requests. This could lead to further exploits, such as session hijacking or response splitting.

Affected Version(s)

drogonframework/drogon 0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alessio Della Libera - Snyk Research Team
.