Pluto is a superset of Lua 5.4 with a focus on general-purpose programming. Scripts passing user-controlled values to http.request header values are affected. An attacker could use this to send arbitrary requests, potentially leveraging authentication tokens provided in the same headers table.
References
Configurations
No configuration.
History
11 Sep 2024, 16:26
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
10 Sep 2024, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-09-10 22:15
Updated : 2024-09-11 16:26
NVD link : CVE-2024-45597
Mitre link : CVE-2024-45597
CVE.ORG link : CVE-2024-45597
JSON object : View
Products Affected
No product.
CWE
CWE-93
Improper Neutralization of CRLF Sequences ('CRLF Injection')