CVE-2022-35948
Vulnerability Summary
Timeline
Description
undici is an HTTP/1.1 client, written from scratch for Node.js.`=< undici@5.8.0` users are vulnerable to _CRLF Injection_ on headers when using unsanitized input as request headers, more specifically, inside the `content-type` header. Example: ``` import { request } from 'undici' const unsanitizedContentTypeInput = 'application/json\r\n\r\nGET /foo2 HTTP/1.1' await request('http://localhost:3000, { method: 'GET', headers: { 'content-type': unsanitizedContentTypeInput }, }) ``` The above snippet will perform two requests in a single `request` API call: 1) `http://localhost:3000/` 2) `http://localhost:3000/foo2` This issue was patched in Undici v5.8.1. Sanitize input when sending content-type headers using user input as a workaround.
CVSS Metrics
- v3.1•MEDIUM•Score: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS Trends
Current EPSS score: 1.27%• Percentile: 68%
Techniques & Countermeasures
- CWE-74•Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
- CWE-93•Improper Neutralization of CRLF Sequences ('CRLF Injection')
The product uses CRLF (carriage return line feeds) as a special element, e.g. to separate lines or records, but it does not neutralize or incorrectly neutralizes CRLF sequences from inputs.
Affected Systems
- debian•node-undici
< 5.8.2+dfsg1+~cs18.9.18.1-1 | < 5.8.2+dfsg1+~cs18.9.18.1-1 | < 5.8.2+dfsg1+~cs18.9.18.1-1
- nodejs•undici
=< 5.8.0 | < 5.8.2
- Npm•undici
< 5.8.2
References (6)
- https://github.com/nodejs/undici/releases/tag/v5.8.2
- https://github.com/nodejs/undici/security/advisories/GHSA-f772-66g8-q5h3
- https://github.com/nodejs/undici/commit/66165d604fd0aee70a93ed5c44ad4cc2df395f80
- https://nvd.nist.gov/vuln/detail/CVE-2022-35948
- https://github.com/nodejs/undici
- https://security-tracker.debian.org/tracker/CVE-2022-35948