HTTP response splitting in FortiOS - CVE-2022-42472
Published: February 17, 2023
Vulnerability details
The vulnerability allows a remote user to perform HTTP splitting attacks.
The vulnerability exists due to software does not correctly process CRLF character sequences. A remote user can send specially crafted request containing CRLF sequence and inject arbitrary HTTP headers.
Successful exploitation of the vulnerability may allow an attacker perform cache poisoning attack.
Affected software
FortiProxy
How to mitigate CVE-2022-42472
FortiProxy - addressed in versions 2.0.11, 7.0.8, 7.2.2