CVE-2022-23439: `Host` header injection
A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the Host header points to an arbitrary webserver
Other sources
An externally controlled reference to a resource in another sphere vulnerability [CWE-610] in multiple products may allow an unauthenticated attacker to poison web caches between the device and the attacker via crafted HTTP requests, where the Host header points to an arbitrary webserver.
— FortiGuard
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-23439?
CVE-2022-23439 is classified with a medium severity level, indicating a potential risk to affected systems.
How can I mitigate CVE-2022-23439?
To remediate CVE-2022-23439, upgrade affected Fortinet products to versions released after 7.4.3 for FortiManager and FortiAnalyzer, 7.0.3 for FortiMail, and other respective versions for other products.
Which Fortinet products are affected by CVE-2022-23439?
CVE-2022-23439 affects FortiManager, FortiMail, FortiAnalyzer, FortiVoice, FortiProxy, FortiRecorder, among others.
Is there a known exploit for CVE-2022-23439?
There is currently no public information regarding known exploits specifically targeting CVE-2022-23439.
What types of vulnerabilities does CVE-2022-23439 represent?
CVE-2022-23439 represents an externally controlled reference to a resource in another sphere, which can lead to unauthorized access in affected Fortinet systems.