Опубликовано: 07 фев. 2020
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS2: 7.5
CVSS3: 9.8
Описание
HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed
Релиз | Статус | Примечание |
---|---|---|
bionic | ignored | end of standard support, was needs-triage |
devel | not-affected | 10.19.0~dfsg-3ubuntu1 |
eoan | ignored | end of life |
esm-apps/bionic | released | 8.10.0~dfsg-2ubuntu0.4+esm2 |
esm-apps/focal | not-affected | 10.19.0~dfsg-3ubuntu1 |
esm-apps/jammy | not-affected | 10.19.0~dfsg-3ubuntu1 |
esm-apps/xenial | released | 4.2.6~dfsg-1ubuntu4.2+esm2 |
esm-infra-legacy/trusty | ignored | regressions likely |
focal | not-affected | 10.19.0~dfsg-3ubuntu1 |
groovy | not-affected | 10.19.0~dfsg-3ubuntu1 |
Показывать по
10
EPSS
Процентиль: 97%
0.33914
Средний
7.5 High
CVSS2
9.8 Critical
CVSS3
Связанные уязвимости
CVSS3: 7.1
redhat
больше 5 лет назад
HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed
CVSS3: 9.8
nvd
больше 5 лет назад
HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed
CVSS3: 9.8
debian
больше 5 лет назад
HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payl ...
CVSS3: 9.8
github
около 3 лет назад
HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed
EPSS
Процентиль: 97%
0.33914
Средний
7.5 High
CVSS2
9.8 Critical
CVSS3