目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2024-45302— RestSharp 安全漏洞

一分钟漏洞结论

影响对象
restsharp RestSharp
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

RestSharp是RestSharp开源的一个 .NET HTTP 客户端库。具有自动序列化和反序列化、请求和响应类型检测功能。 RestSharp 107之前版本存在安全漏洞,该漏洞源于在处理HTTP头信息时未对CRLF字符进行验证,允许攻击者注入额外的HTTP头信息或走私请求。

CVSS 6.1 · Medium EPSS 0.32% · P24
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2024-45302 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
CRLF Injection in RestSharp's `RestRequest.AddHeader` method
来源: CVE Program / CVE List V5
Vulnerability Description
RestSharp is a Simple REST and HTTP API Client for .NET. The second argument to `RestRequest.AddHeader` (the header value) is vulnerable to CRLF injection. The same applies to `RestRequest.AddOrUpdateHeader` and `RestClient.AddDefaultHeader`. The way HTTP headers are added to a request is via the `HttpHeaders.TryAddWithoutValidation` method which does not check for CRLF characters in the header value. This means that any headers from a `RestSharp.RequestHeaders` object are added to the request in such a way that they are vulnerable to CRLF-injection. In general, CRLF-injection into a HTTP header (when using HTTP/1.1) means that one can inject additional HTTP headers or smuggle whole HTTP requests. If an application using the RestSharp library passes a user-controllable value through to a header, then that application becomes vulnerable to CRLF-injection. This is not necessarily a security issue for a command line application like the one above, but if such code were present in a web application then it becomes vulnerable to request splitting (as shown in the PoC) and thus Server Side Request Forgery. Strictly speaking this is a potential vulnerability in applications using RestSharp, not in RestSharp itself, but I would argue that at the very least there needs to be a warning about this behaviour in the RestSharp documentation. RestSharp has addressed this issue in version 112.0.0. All users are advised to upgrade. There are no known workarounds for this vulnerability.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
来源: CVE Program / CVE List V5
Vulnerability Type
对CRLF序列的转义处理不恰当(CRLF注入)
来源: CVE Program / CVE List V5
Vulnerability Title
RestSharp 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
RestSharp是RestSharp开源的一个 .NET HTTP 客户端库。具有自动序列化和反序列化、请求和响应类型检测功能。 RestSharp 107之前版本存在安全漏洞,该漏洞源于在处理HTTP头信息时未对CRLF字符进行验证,允许攻击者注入额外的HTTP头信息或走私请求。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商 产品 影响版本 CPE 订阅
restsharp RestSharp >= 107, < 112.0.0 -

二、漏洞 CVE-2024-45302 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2024-45302 的情报信息

登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2024-45302

暂无评论


发表评论