VDB
Sign up
HIGH7.5

GHSA-j9f9-8j39-4g97

CodeIgniter HTTP Header Injection

Quick fix

GHSA-j9f9-8j39-4g97 — codeigniter4/framework: upgrade to the fixed version with the command below.

composer require codeigniter4/framework:^3.1.4

Details

British Columbia Institute of Technology CodeIgniter 3.1.3 is vulnerable to HTTP Header Injection in the set_status_header() common function under Apache resulting in HTTP Header Injection flaws.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/codeigniter4/framework
Introduced in: 3.1.3Fixed in: 3.1.4
Fixcomposer require codeigniter4/framework:^3.1.4

References