Medium severity5.4NVD Advisory· Published Jan 3, 2023· Updated Jun 17, 2026
CVE-2022-42471
CVE-2022-42471
Description
An improper neutralization of CRLF sequences in HTTP headers ('HTTP Response Splitting') vulnerability [CWE-113] In FortiWeb version 7.0.0 through 7.0.2, FortiWeb version 6.4.0 through 6.4.2, FortiWeb version 6.3.6 through 6.3.20 may allow an authenticated and remote attacker to inject arbitrary headers.
Affected products
9cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*+ 8 more
- cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*range: >=6.3.6,<=6.3.21
- cpe:2.3:a:fortinet:fortiweb:6.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortiweb:6.4.1:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortiweb:6.4.2:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortiweb:7.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortiweb:7.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortiweb:7.0.2:*:*:*:*:*:*:*
- (no CPE)range: 7.0.0-7.0.2, 6.4.0-6.4.2, 6.3.6-6.3.20
- (no CPE)range: 7.0.0
Patches
Vulnerability mechanics
References
1- fortiguard.com/psirt/FG-IR-22-250nvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.