Описание
HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed
A flaw was found in the Node.js code where a specially crafted HTTP(s) request sent to a Node.js server failed to properly process the HTTP(s) headers, resulting in a request smuggling attack. An attacker can use this flaw to alter a request sent as an authenticated user if the Node.js server is deployed behind a proxy server that reuses connections.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Quay 3 | quay | Not affected | ||
Red Hat Enterprise Linux 7 | http-parser | Fixed | RHSA-2020:0703 | 04.03.2020 |
Red Hat Enterprise Linux 7.6 Extended Update Support | http-parser | Fixed | RHSA-2020:1510 | 21.04.2020 |
Red Hat Enterprise Linux 8 | nodejs | Fixed | RHSA-2020:0579 | 25.02.2020 |
Red Hat Enterprise Linux 8 | nodejs | Fixed | RHSA-2020:0598 | 25.02.2020 |
Red Hat Enterprise Linux 8 | http-parser | Fixed | RHSA-2020:0708 | 04.03.2020 |
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions | nodejs | Fixed | RHSA-2020:0573 | 24.02.2020 |
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions | http-parser | Fixed | RHSA-2020:0707 | 04.03.2020 |
Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs10-nodejs | Fixed | RHSA-2020:0597 | 25.02.2020 |
Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs12-nodejs | Fixed | RHSA-2020:0602 | 25.02.2020 |
Показывать по
Дополнительная информация
Статус:
7.1 High
CVSS3
Связанные уязвимости
HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed
HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed
HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payl ...
HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed
7.1 High
CVSS3