Versions of the package yhirose/cpp-httplib before 0.12.4...
High severity
Unreviewed
Published
May 30, 2023
to the GitHub Advisory Database
•
Updated Oct 28, 2024
Description
Published by the National Vulnerability Database
May 30, 2023
Published to the GitHub Advisory Database
May 30, 2023
Last updated
Oct 28, 2024
Versions of the package yhirose/cpp-httplib before 0.12.4 are vulnerable to CRLF Injection when untrusted user input is used to set the content-type header in the HTTP .Patch, .Post, .Put and .Delete requests. This can lead to logical errors and other misbehaviors.
Note: This issue is present due to an incomplete fix for CVE-2020-11709.
References