CVE-2022-35948
published 2022-08-15CVE-2022-35948: undici is an HTTP/1.1 client, written from scratch for Node.js.`=< [email protected]` users are vulnerable to _CRLF Injection_ on headers when using unsanitized…
PriorityP429medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
1.20%
64.6th percentile
undici is an HTTP/1.1 client, written from scratch for Node.js.`=< [email protected]` users are vulnerable to _CRLF Injection_ on headers when using unsanitized input as request headers, more specifically, inside the `content-type` header. Example: ``` import { request } from 'undici' const unsanitizedContentTypeInput = 'application/json\r\n\r\nGET /foo2 HTTP/1.1' await request('http://localhost:3000, { method: 'GET', headers: { 'content-type': unsanitizedContentTypeInput }, }) ``` The above snippet will perform two requests in a single `request` API call: 1) `http://localhost:3000/` 2) `http://localhost:3000/foo2` This issue was patched in Undici v5.8.1. Sanitize input when sending content-type headers using user input as a workaround.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | node-undici | < node-undici 5.8.2+dfsg1+~cs18.9.18.1-1 (bookworm) | node-undici 5.8.2+dfsg1+~cs18.9.18.1-1 (bookworm) |
| nodejs | undici | < 5.8.2 | 5.8.2 |
| nodejs | undici | — | — |
| nodejs | undici | >= 0 < 5.8.2 | 5.8.2 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
nodejs: undici vulnerable to CRLF via content headers
vendor_redhat·2022-08-09·CVSS 5.3
CVE-2022-35948 [MEDIUM] CWE-93 nodejs: undici vulnerable to CRLF via content headers
nodejs: undici vulnerable to CRLF via content headers
undici is an HTTP/1.1 client, written from scratch for Node.js.`=< [email protected]` users are vulnerable to _CRLF Injection_ on headers when using unsanitized input as request headers, more specifically, inside the `content-type` header. Example: ``` import { request } from 'undici' const unsanitizedContentTypeInput = 'application/json\r\n\r\nGET /foo2 HTTP/1.1' await request('http://localhost:3000, { method: 'GET', headers: { 'content-type': unsanitizedContentTypeInput }, }) ``` The above snippet will perform two requests in a single `request` API call: 1) `http://localhost:3000/` 2) `http://localhost:3000/foo2` This issue was patched in Undici v5.8.1. Sanitize input when sending content-type headers using user input as a workaround.
A
Debian
CVE-2022-35948: node-undici - undici is an HTTP/1.1 client, written from scratch for Node.js.`=< [email protected]`...
vendor_debian·2022·CVSS 5.3
CVE-2022-35948 [MEDIUM] CVE-2022-35948: node-undici - undici is an HTTP/1.1 client, written from scratch for Node.js.`=< [email protected]`...
undici is an HTTP/1.1 client, written from scratch for Node.js.`=< [email protected]` users are vulnerable to _CRLF Injection_ on headers when using unsanitized input as request headers, more specifically, inside the `content-type` header. Example: ``` import { request } from 'undici' const unsanitizedContentTypeInput = 'application/json\r\n\r\nGET /foo2 HTTP/1.1' await request('http://localhost:3000, { method: 'GET', headers: { 'content-type': unsanitizedContentTypeInput }, }) ``` The above snippet will perform two requests in a single `request` API call: 1) `http://localhost:3000/` 2) `http://localhost:3000/foo2` This issue was patched in Undici v5.8.1. Sanitize input when sending content-type headers using user input as a workaround.
Scope: local
bookworm: resolved (fixed in 5.8.2+dfsg1+~cs1
GHSA
Nodejs ‘undici’ vulnerable to CRLF Injection via Content-Type
ghsa·2022-08-18
CVE-2022-35948 [MEDIUM] CWE-74 Nodejs ‘undici’ vulnerable to CRLF Injection via Content-Type
Nodejs ‘undici’ vulnerable to CRLF Injection via Content-Type
### Impact
`=< [email protected]` users are vulnerable to _CRLF Injection_ on headers when using unsanitized input as request headers, more specifically, inside the `content-type` header.
Example:
```
import { request } from 'undici'
const unsanitizedContentTypeInput = 'application/json\r\n\r\nGET /foo2 HTTP/1.1'
await request('http://localhost:3000, {
method: 'GET',
headers: {
'content-type': unsanitizedContentTypeInput
},
})
```
The above snippet will perform two requests in a single `request` API call:
1) `http://localhost:3000/`
2) `http://localhost:3000/foo2`
### Patches
This issue was patched in Undici v5.8.1
### Workarounds
Sanitize input when sending content-type headers using user input.
## For more information
OSV
Nodejs ‘undici’ vulnerable to CRLF Injection via Content-Type
osv·2022-08-18
CVE-2022-35948 [MEDIUM] Nodejs ‘undici’ vulnerable to CRLF Injection via Content-Type
Nodejs ‘undici’ vulnerable to CRLF Injection via Content-Type
### Impact
`=< [email protected]` users are vulnerable to _CRLF Injection_ on headers when using unsanitized input as request headers, more specifically, inside the `content-type` header.
Example:
```
import { request } from 'undici'
const unsanitizedContentTypeInput = 'application/json\r\n\r\nGET /foo2 HTTP/1.1'
await request('http://localhost:3000, {
method: 'GET',
headers: {
'content-type': unsanitizedContentTypeInput
},
})
```
The above snippet will perform two requests in a single `request` API call:
1) `http://localhost:3000/`
2) `http://localhost:3000/foo2`
### Patches
This issue was patched in Undici v5.8.1
### Workarounds
Sanitize input when sending content-type headers using user input.
## For more information
OSV
CVE-2022-35948: undici is an HTTP/1
osv·2022-08-15·CVSS 5.3
CVE-2022-35948 [MEDIUM] CVE-2022-35948: undici is an HTTP/1
undici is an HTTP/1.1 client, written from scratch for Node.js.`=< [email protected]` users are vulnerable to _CRLF Injection_ on headers when using unsanitized input as request headers, more specifically, inside the `content-type` header. Example: ``` import { request } from 'undici' const unsanitizedContentTypeInput = 'application/json\r\n\r\nGET /foo2 HTTP/1.1' await request('http://localhost:3000, { method: 'GET', headers: { 'content-type': unsanitizedContentTypeInput }, }) ``` The above snippet will perform two requests in a single `request` API call: 1) `http://localhost:3000/` 2) `http://localhost:3000/foo2` This issue was patched in Undici v5.8.1. Sanitize input when sending content-type headers using user input as a workaround.
No detection rules found.
No public exploits indexed.
https://github.com/nodejs/undici/commit/66165d604fd0aee70a93ed5c44ad4cc2df395f80https://github.com/nodejs/undici/releases/tag/v5.8.2https://github.com/nodejs/undici/security/advisories/GHSA-f772-66g8-q5h3https://github.com/nodejs/undici/commit/66165d604fd0aee70a93ed5c44ad4cc2df395f80https://github.com/nodejs/undici/releases/tag/v5.8.2https://github.com/nodejs/undici/security/advisories/GHSA-f772-66g8-q5h3
2022-08-15
Published