Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-41834

Опубликовано: 19 сент. 2023
Источник: nvd
CVSS3: 6.1
EPSS Низкий

Описание

Improper Neutralization of CRLF Sequences in HTTP Headers in Apache Flink Stateful Functions 3.1.0, 3.1.1 and 3.2.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted HTTP requests. Attackers could potentially inject malicious content into the HTTP response that is sent to the user's browser.

Users should upgrade to Apache Flink Stateful Functions version 3.3.0.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:apache:flink_stateful_functions:*:*:*:*:*:*:*:*
Версия от 3.1.0 (включая) до 3.2.0 (включая)

EPSS

Процентиль: 80%
0.01372
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-74
CWE-74

Связанные уязвимости

CVSS3: 6.1
github
больше 2 лет назад

Improper Neutralization of CRLF Sequences in HTTP Headers in Apache Flink Stateful Functions 3.1.0, 3.1.1 and 3.2.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted HTTP requests. Attackers could potentially inject malicious content into the HTTP response that is sent to the user's browser. Users should upgrade to Apache Flink Stateful Functions version 3.3.0.

EPSS

Процентиль: 80%
0.01372
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-74
CWE-74