Pluto is a superset of Lua 5.4 with a focus on general-purpose programming. Scripts passing user-controlled values to http.request header values are affected. An attacker could use this to send arbitrary requests, potentially leveraging authentication tokens provided in the same headers table.
History

Wed, 11 Sep 2024 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Pluto
Pluto pluto
CPEs cpe:2.3:a:pluto:pluto:*:*:*:*:*:*:*:*
Vendors & Products Pluto
Pluto pluto
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 10 Sep 2024 21:45:00 +0000

Type Values Removed Values Added
Description Pluto is a superset of Lua 5.4 with a focus on general-purpose programming. Scripts passing user-controlled values to http.request header values are affected. An attacker could use this to send arbitrary requests, potentially leveraging authentication tokens provided in the same headers table.
Title Pluto's http.request allows CR and LF in header values
Weaknesses CWE-93
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-09-10T21:42:47.530Z

Updated: 2024-09-11T13:28:10.303Z

Reserved: 2024-09-02T16:00:02.423Z

Link: CVE-2024-45597

cve-icon Vulnrichment

Updated: 2024-09-11T13:27:59.240Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-09-10T22:15:01.967

Modified: 2024-09-11T16:26:11.920

Link: CVE-2024-45597

cve-icon Redhat

No data.