CVE-2022-38333

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
19/09/2022
Last modified:
07/11/2023

Description

Openwrt before v21.02.3 and Openwrt v22.03.0-rc6 were discovered to contain two skip loops in the function header_value(). This vulnerability allows attackers to access sensitive information via a crafted HTTP request.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:openwrt:openwrt:*:*:*:*:*:*:*:* 21.02.3 (excluding)
cpe:2.3:o:openwrt:openwrt:22.03.0:rc6:*:*:*:*:*:*