flawopen.com/Teardowns/cve-2022-31150-undici-crlf-injection-ssrf
Analyse technique détaillée du code source et mesures de durcissement pour vulnerabilidade : How unvetted carriage return characters in HTTP header values allowed attackers to split outgoing HTTP requests in Node.js globalThis.fetch().
Imaginez que vous envoyiez une lettre scellée par la poste disant : "Expédiez 10 caisses de pommes". Mais vous glissez discrètement une seconde feuille officielle falsifiée disant : "STOP. IGNOREZ CE QUI PRÉCÈDE. TRANSFÉREZ TOUS LES FONDS À EVIL CORP". L'agent postal lit les pages dans l'ordre et traite la seconde feuille comme une toute nouvelle lettre officielle, envoyant vos fonds directement à l'attaquant.
Undicifetch() implementation.CRLF Injection\r) and Line Feed (\n) characters into HTTP headers to create a new header or a whole new request.HTTP Request SplittingSSRF (Server-Side Request Forgery)169.254.169.254).La cause fondamentale provient de paramètres de limites non validés dans les systèmes open source, permettant une désynchronisation d'état et le contournement des contrôles de sécurité.
Mécanisme technique d'exploitation : An attacker supplies a crafted header value: Admin\r\nHost: 169.254.169.254.
Mécanisme technique d'exploitation : The Node.js backend calls fetch(url, { headers: { 'X-User': input } }).
Mécanisme technique d'exploitation : Undici serializes the headers without sanitizing \r\n, injecting the forged Host header.
Mécanisme technique d'exploitation : The internal proxy directs the request to the cloud metadata service, exposing AWS/GCP credentials.
// VULNERABLE: lib/core/request.js before patch
function addHeader(headers, key, value) {
// ROOT CAUSE:
// Does not sanitize or reject carriage return (\r) and line feed (\n) in values!
// Allows attackers to split headers and inject arbitrary HTTP directives!
headers[key] = value;
}
// SECURE: lib/core/request.js patch
function addHeader(headers, key, value) {
// 1. Strict regex checking for dangerous control characters
const INVALID_HEADER_CHAR_REGEX = /[\r\n]/;
if (INVALID_HEADER_CHAR_REGEX.test(key) || INVALID_HEADER_CHAR_REGEX.test(value)) {
throw new TypeError(`Invalid character in header content: ["${key}": "${value}"]`);
}
headers[key] = value;
}
\r and \n characters from HTTP request header keys and values.169.254.169.254, 10.0.0.0/8, 127.0.0.1) using egress firewall rules.undici and Node.js dependencies updated to latest patch releases.