CVE-2023-41834

MEDIUM WAF: High
CVSS 6.1 Published: 2023-09-19
CWE-113

Improper Neutralization of CRLF Sequences in HTTP Headers in Apache Flink Stateful Functions 3.1.0, 3.1.1 and 3.2.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted HTTP requests. Attackers could potentially inject malicious content into the HTTP response that is sent to the user's browser. Users should upgrade to Apache Flink Stateful Functions version 3.3.0.

WAF Coverage Analysis

HTTP Response Splitting High WAF Coverage

OWASP: A03:2021 Injection

921xxx - Protocol Attack

Affected Software

VendorProductVersion
apacheflink_stateful_functions3.1.0 - 3.2.0

References

Back to CVE Database