Improper Neutralization of CRLF Sequences in HTTP Headers in Apache Flink Stateful Functions 3.1.0, 3.1.1 and 3.2.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted HTTP requests. Attackers could potentially inject malicious content into the HTTP response that is sent to the user's browser. Users should upgrade to Apache Flink Stateful Functions version 3.3.0.
History

Wed, 25 Sep 2024 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2023-09-19T12:34:16.970Z

Updated: 2024-09-25T14:19:29.675Z

Reserved: 2023-09-01T20:38:56.287Z

Link: CVE-2023-41834

cve-icon Vulnrichment

Updated: 2024-08-02T19:09:49.376Z

cve-icon NVD

Status : Analyzed

Published: 2023-09-19T13:16:22.333

Modified: 2023-09-22T19:24:02.097

Link: CVE-2023-41834

cve-icon Redhat

No data.