Back to Vulnerability Directory
MEDIUMNot covered

CVE-2023-41834

Apache Flink Stateful Functions: HTTP header injection through CRLF sequences

Technology

Apache Flink Stateful Functions

CVSS Score

6.1 / 10.0

Affected Versions

Apache Flink Stateful Functions 3.1.0, 3.1.1 and 3.2.0

Upstream Fix

Stateful Functions 3.3.0

Published

September 19, 2023

OSSeva Coverage

Not covered

Description

Stateful Functions does not neutralize CRLF sequences in HTTP headers, so remote attackers can inject headers and split HTTP responses with crafted requests, potentially sending malicious content to a user's browser.

Upstream record: NVD · CVE.org

Is your Apache Flink Stateful Functions deployment affected?

If you're running Apache Flink Stateful Functions 3.1.0, 3.1.1 and 3.2.0, you need this patch. Book a discovery call to get covered.