Количество 17
Количество 17

BDU:2024-08734
Уязвимость метода undici.request клиента HTTP/1.1 Undici программной платформы Node.js, позволяющая нарушителю внедрить произвольные HTTP-заголовки

CVE-2023-23936
Undici is an HTTP/1.1 client for Node.js. Starting with version 2.0.0 and prior to version 5.19.1, the undici library does not protect `host` HTTP header from CRLF injection vulnerabilities. This issue is patched in Undici v5.19.1. As a workaround, sanitize the `headers.host` string before passing to undici.

CVE-2023-23936
Undici is an HTTP/1.1 client for Node.js. Starting with version 2.0.0 and prior to version 5.19.1, the undici library does not protect `host` HTTP header from CRLF injection vulnerabilities. This issue is patched in Undici v5.19.1. As a workaround, sanitize the `headers.host` string before passing to undici.

CVE-2023-23936
Undici is an HTTP/1.1 client for Node.js. Starting with version 2.0.0 and prior to version 5.19.1, the undici library does not protect `host` HTTP header from CRLF injection vulnerabilities. This issue is patched in Undici v5.19.1. As a workaround, sanitize the `headers.host` string before passing to undici.

CVE-2023-23936
CVE-2023-23936
Undici is an HTTP/1.1 client for Node.js. Starting with version 2.0.0 ...
GHSA-5r9g-qh6m-jxff
CRLF Injection in Nodejs ‘undici’ via host

SUSE-SU-2023:0738-1
Security update for nodejs18

SUSE-SU-2023:0715-1
Security update for nodejs18

SUSE-SU-2023:0673-1
Security update for nodejs16

SUSE-SU-2023:0609-1
Security update for nodejs16

SUSE-SU-2023:0608-1
Security update for nodejs16

RLSA-2023:2655
Moderate: nodejs and nodejs-nodemon security, bug fix, and enhancement update
ELSA-2023-2655
ELSA-2023-2655: nodejs and nodejs-nodemon security, bug fix, and enhancement update (MODERATE)
ELSA-2023-1583
ELSA-2023-1583: nodejs:18 security, bug fix, and enhancement update (MODERATE)
ELSA-2023-2654
ELSA-2023-2654: nodejs:18 security, bug fix, and enhancement update (MODERATE)
ELSA-2023-1582
ELSA-2023-1582: nodejs:16 security, bug fix, and enhancement update (MODERATE)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | BDU:2024-08734 Уязвимость метода undici.request клиента HTTP/1.1 Undici программной платформы Node.js, позволяющая нарушителю внедрить произвольные HTTP-заголовки | CVSS3: 6.5 | 0% Низкий | больше 2 лет назад |
![]() | CVE-2023-23936 Undici is an HTTP/1.1 client for Node.js. Starting with version 2.0.0 and prior to version 5.19.1, the undici library does not protect `host` HTTP header from CRLF injection vulnerabilities. This issue is patched in Undici v5.19.1. As a workaround, sanitize the `headers.host` string before passing to undici. | CVSS3: 6.5 | 0% Низкий | больше 2 лет назад |
![]() | CVE-2023-23936 Undici is an HTTP/1.1 client for Node.js. Starting with version 2.0.0 and prior to version 5.19.1, the undici library does not protect `host` HTTP header from CRLF injection vulnerabilities. This issue is patched in Undici v5.19.1. As a workaround, sanitize the `headers.host` string before passing to undici. | CVSS3: 6.5 | 0% Низкий | больше 2 лет назад |
![]() | CVE-2023-23936 Undici is an HTTP/1.1 client for Node.js. Starting with version 2.0.0 and prior to version 5.19.1, the undici library does not protect `host` HTTP header from CRLF injection vulnerabilities. This issue is patched in Undici v5.19.1. As a workaround, sanitize the `headers.host` string before passing to undici. | CVSS3: 6.5 | 0% Низкий | больше 2 лет назад |
![]() | CVSS3: 5.4 | 0% Низкий | больше 2 лет назад | |
CVE-2023-23936 Undici is an HTTP/1.1 client for Node.js. Starting with version 2.0.0 ... | CVSS3: 6.5 | 0% Низкий | больше 2 лет назад | |
GHSA-5r9g-qh6m-jxff CRLF Injection in Nodejs ‘undici’ via host | CVSS3: 4.6 | 0% Низкий | больше 2 лет назад | |
![]() | SUSE-SU-2023:0738-1 Security update for nodejs18 | больше 2 лет назад | ||
![]() | SUSE-SU-2023:0715-1 Security update for nodejs18 | больше 2 лет назад | ||
![]() | SUSE-SU-2023:0673-1 Security update for nodejs16 | больше 2 лет назад | ||
![]() | SUSE-SU-2023:0609-1 Security update for nodejs16 | больше 2 лет назад | ||
![]() | SUSE-SU-2023:0608-1 Security update for nodejs16 | больше 2 лет назад | ||
![]() | RLSA-2023:2655 Moderate: nodejs and nodejs-nodemon security, bug fix, and enhancement update | около 2 лет назад | ||
ELSA-2023-2655 ELSA-2023-2655: nodejs and nodejs-nodemon security, bug fix, and enhancement update (MODERATE) | около 2 лет назад | |||
ELSA-2023-1583 ELSA-2023-1583: nodejs:18 security, bug fix, and enhancement update (MODERATE) | около 2 лет назад | |||
ELSA-2023-2654 ELSA-2023-2654: nodejs:18 security, bug fix, and enhancement update (MODERATE) | около 2 лет назад | |||
ELSA-2023-1582 ELSA-2023-1582: nodejs:16 security, bug fix, and enhancement update (MODERATE) | около 2 лет назад |
Уязвимостей на страницу