VYPR
Medium severity5.4NVD Advisory· Published Jan 3, 2023· Updated Jun 17, 2026

CVE-2022-42471

CVE-2022-42471

Description

An improper neutralization of CRLF sequences in HTTP headers ('HTTP Response Splitting') vulnerability [CWE-113] In FortiWeb version 7.0.0 through 7.0.2, FortiWeb version 6.4.0 through 6.4.2, FortiWeb version 6.3.6 through 6.3.20 may allow an authenticated and remote attacker to inject arbitrary headers.

Affected products

9
  • Fortinet/Fortiweb9 versions
    cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*+ 8 more
    • cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*range: >=6.3.6,<=6.3.21
    • cpe:2.3:a:fortinet:fortiweb:6.4.0:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortiweb:6.4.1:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortiweb:6.4.2:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortiweb:7.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortiweb:7.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortiweb:7.0.2:*:*:*:*:*:*:*
    • (no CPE)range: 7.0.0-7.0.2, 6.4.0-6.4.2, 6.3.6-6.3.20
    • (no CPE)range: 7.0.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.