Versions of the package yhirose/cpp-httplib before 0.12.4 are vulnerable to CRLF Injection when untrusted user input is used to set the content-type header in the HTTP .Patch, .Post, .Put and .Delete requests. This can lead to logical errors and other misbehaviors. Note: This issue is present due to an incomplete fix for CVE-2020-11709.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "0.14.3+ds-1.1build2", "binary_name": "libcpp-httplib-dev" }, { "binary_version": "0.14.3+ds-1.1build2", "binary_name": "libcpp-httplib0.14t64" }, { "binary_version": "0.14.3+ds-1.1build2", "binary_name": "libcpp-httplib0.14t64-dbgsym" } ] }