CRLF Injection in Nodejs ‘undici’ via host
Published Feb 16, 2023
6.5
MEDIUMCVSS 3.1
EPSS 1.13%
Description
Undici is an HTTP/1.1 client for Node.js. Starting with version 2.0.0 and prior to version 5.19.1, the undici library does not protect `host` HTTP header from CRLF injection vulnerabilities. This issue is patched in Undici v5.19.1. As a workaround, sanitize the `headers.host` string before passing to undici.
Affected products
-
- Version >=2.0.0, < 5.19.1StatusaffectedConstraints-
- Version
No data.
Red Hat Enterprise Linux 8
nodejs:16-8070020230314140722.bd1311ed
Fixed · RHSA-2023:1582
Red Hat Enterprise Linux 8
nodejs:18-8070020230322080930.bd1311ed
Fixed · RHSA-2023:1583
Red Hat Enterprise Linux 9
nodejs-1:16.19.1-1.el9_2
Fixed · RHSA-2023:2655
Red Hat Enterprise Linux 9
nodejs:18-9020020230327152102.rhel9
Fixed · RHSA-2023:2654
Red Hat Enterprise Linux 9.0 Extended Update Support
nodejs-1:16.20.2-1.el9_0
Fixed · RHSA-2023:5533
Red Hat 3scale API Management Platform 2
3scale-amp-system-container
Will not fix
Red Hat Enterprise Linux 8
nodejs
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | nodejs:16-8070020230314140722.bd1311ed | Fixed | RHSA-2023:1582 |
| Red Hat Enterprise Linux 8 | nodejs:18-8070020230322080930.bd1311ed | Fixed | RHSA-2023:1583 |
| Red Hat Enterprise Linux 9 | nodejs-1:16.19.1-1.el9_2 | Fixed | RHSA-2023:2655 |
| Red Hat Enterprise Linux 9 | nodejs:18-9020020230327152102.rhel9 | Fixed | RHSA-2023:2654 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | nodejs-1:16.20.2-1.el9_0 | Fixed | RHSA-2023:5533 |
| Red Hat 3scale API Management Platform 2 | 3scale-amp-system-container | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | nodejs | Not affected | n/a |
undici
npm
Introduced 2.0.0 Fixed 5.19.1
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | undici | 2.0.0 | 5.19.1 |
Remediation
No remediation recorded yet.
References (10)
- https://access.redhat.com/security/cve/CVE-2023-23936 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2172190 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-0633 Advisory
- https://github.com/advisories/GHSA-5r9g-qh6m-jxff Advisory
- https://github.com/nodejs/undici/commit/a2eff05401358f6595138df963837c24348f2034 x_refsource_MISCPatch
- https://github.com/nodejs/undici/releases/tag/v5.19.1 x_refsource_MISCRelease Notes
- https://github.com/nodejs/undici/security/advisories/GHSA-5r9g-qh6m-jxff x_refsource_CONFIRMVendor Advisory
- https://hackerone.com/reports/1820955 x_refsource_MISCExploitThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-23936
- https://www.cve.org/CVERecord?id=CVE-2023-23936
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2023-23936 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2172190 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-0633 | Advisory | |
| https://github.com/advisories/GHSA-5r9g-qh6m-jxff | Advisory | |
| https://github.com/nodejs/undici/commit/a2eff05401358f6595138df963837c24348f2034 | x_refsource_MISCPatch | |
| https://github.com/nodejs/undici/releases/tag/v5.19.1 | x_refsource_MISCRelease Notes | |
| https://github.com/nodejs/undici/security/advisories/GHSA-5r9g-qh6m-jxff | x_refsource_CONFIRMVendor Advisory | |
| https://hackerone.com/reports/1820955 | x_refsource_MISCExploitThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2023-23936 | ||
| https://www.cve.org/CVERecord?id=CVE-2023-23936 |
Change history (0)
No recorded changes yet.