CRLF injection in undici - CVE-2022-31150

 

CRLF injection in undici - CVE-2022-31150

Published: September 11, 2022


Vulnerability identifier: #VU67163
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-31150
CWE-ID: CWE-93
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to inject arbitrary data in server response.

The vulnerability exists due to insufficient validation of attacker-supplied data. A remote attacker can pass specially crafted data to the application containing CR-LF characters and modify application behavior.


Affected software

undici
Red Hat Advanced Cluster Management for Kubernetes
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Storage
SUSE Linux Enterprise Module for Web Scripting
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
openSUSE Leap
nodejs16-debuginfo
nodejs16-docs
npm16
nodejs16-devel
nodejs16-debugsource
nodejs16
corepack16

How to mitigate CVE-2022-31150

Install updates from vendor's website.

undici - update to 5.8.0
Red Hat Advanced Cluster Management for Kubernetes - update to 2.4.6
nodejs16-debuginfo - addressed in versions 16.17.0-8.9.1, 16.17.0-150300.7.9.1, 16.17.0-150400.3.6.1
nodejs16-docs - addressed in versions 16.17.0-8.9.1, 16.17.0-150300.7.9.1, 16.17.0-150400.3.6.1
npm16 - addressed in versions 16.17.0-8.9.1, 16.17.0-150300.7.9.1, 16.17.0-150400.3.6.1
nodejs16-devel - addressed in versions 16.17.0-8.9.1, 16.17.0-150300.7.9.1, 16.17.0-150400.3.6.1
nodejs16-debugsource - addressed in versions 16.17.0-8.9.1, 16.17.0-150300.7.9.1, 16.17.0-150400.3.6.1
nodejs16 - addressed in versions 16.17.0-8.9.1, 16.17.0-150300.7.9.1, 16.17.0-150400.3.6.1
corepack16 - update to 16.17.0-150400.3.6.1

External References

Related Security Bulletins