Executive brief
HotelRunner B2B, a platform used for travel industry business-to-business operations, contains a security flaw in how it validates digital certificates. This vulnerability could allow an attacker to perform 'HTTP Response Splitting,' which can lead to the hijacking of user sessions or the delivery of malicious content to other users. Organizations using this service should ensure they are using the updated version released after June 4, 2025.
Technical details
A vulnerability exists in HotelRunner B2B due to CWE-297 (Improper Validation of Certificate with Host Mismatch). This flaw allows for HTTP Response Splitting, a technique where an attacker can inject control characters into HTTP headers to split a single response into two. The attack vector is network-based and requires low privileges (PR:L) and user interaction (UI:R). By exploiting this, an attacker can potentially perform cross-site scripting (XSS), cache poisoning, or session hijacking. The issue is addressed in versions released on or after June 4, 2025.
Affected products
- HotelRunner B2B before 04.06.2025
Timeline
- 2025-07-22: advisory: NVD publication date
- 2025-06-04: patched: Issue fixed in versions from this date onwards