Description
An improper neutralization of CRLF sequences in HTTP headers ('HTTP Response Splitting') vulnerability [CWE-113] In FortiWeb version 7.0.0 through 7.0.2, FortiWeb version 6.4.0 through 6.4.2, FortiWeb version 6.3.6 through 6.3.20 may allow an authenticated and remote attacker to inject arbitrary headers.
No analysis available yet.
Remediation
Vendor Solution
Please upgrade to FortiWeb version 7.2.0 or above Please upgrade to FortiWeb version 7.0.3 or above
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-45541 | An improper neutralization of CRLF sequences in HTTP headers ('HTTP Response Splitting') vulnerability [CWE-113] In FortiWeb version 7.0.0 through 7.0.2, FortiWeb version 6.4.0 through 6.4.2, FortiWeb version 6.3.6 through 6.3.20 may allow an authenticated and remote attacker to inject arbitrary headers. |
References
| Link | Providers |
|---|---|
| https://fortiguard.com/psirt/FG-IR-22-250 |
|
History
Tue, 22 Oct 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2024-10-22T20:51:05.460Z
Reserved: 2022-10-07T14:05:36.300Z
Link: CVE-2022-42471
Updated: 2024-08-03T13:10:40.875Z
Status : Modified
Published: 2023-01-03T17:15:10.533
Modified: 2024-11-21T07:25:02.063
Link: CVE-2022-42471
No data.
OpenCVE Enrichment
No data.
EUVD