FG-IR-26-153: Header injection in captive portal authentication form
An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] in FortiOS and FortiProxy captive portal may allow an attacker able to intercept and modify a user's authentication request to inject arbitrary headers via crafted HTTP requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-26-153?
The severity of FG-IR-26-153 is low, rated at 3.1.
How do I fix FG-IR-26-153?
To fix FG-IR-26-153, update FortiOS and FortiProxy to the latest version provided by Fortinet.
What type of vulnerability is FG-IR-26-153?
FG-IR-26-153 is classified as an Improper Neutralization of CRLF Sequences in HTTP Headers vulnerability, also known as HTTP Response Splitting.
Which products are affected by FG-IR-26-153?
The affected products for FG-IR-26-153 include Fortinet FortiOS and Fortinet FortiProxy.
What can an attacker achieve with FG-IR-26-153?
An attacker can exploit FG-IR-26-153 to inject arbitrary headers into a user's authentication request if they can intercept and modify it.