Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-29979 | All versions of the package drogonframework/drogon are vulnerable to CRLF Injection when untrusted user input is used to set request headers in the addHeader function. An attacker can add the \r\n (carriage return line feeds) characters and inject additional headers in the request sent. |
Tue, 19 Nov 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2024-11-19T18:57:08.451Z
Reserved: 2023-02-20T10:28:48.926Z
Link: CVE-2023-26138
Updated: 2024-08-02T11:39:06.797Z
Status : Modified
Published: 2023-07-06T05:15:09.250
Modified: 2024-11-21T07:50:51.387
Link: CVE-2023-26138
No data.
OpenCVE Enrichment
No data.
EUVD