[FEDORA-2021-9818cabe0d] Fedora 35: nodejs

Severity Medium
Affected Packages 1
CVEs 2

2021-10-12, Version 16.11.1 (Current), @danielleadams This is a security

release. ### Notable changes * CVE-2021-22959: HTTP Request Smuggling due
to spaced in headers (Medium) * The http parser accepts requests with a space
(SP) right after the header name before the colon. This can lead to HTTP Request
Smuggling (HRS). More details will be available at
CVE-2021-22959
after publication. * CVE-2021-22960: HTTP Request Smuggling when parsing the
body (Medium) * The parse ignores chunk extensions when parsing the body of
chunked requests. This leads to HTTP Request Smuggling (HRS) under certain
conditions. More details will be available at
CVE-2021-22960
after publication. ## 2021-10-08, Version 16.11.0 (Current), @danielleadams

Notable Changes * crypto * update root certificates (Richard Lau)

#40280 * deps * upgrade npm
to 8.0.0 (npm team) #40369 *
update nghttp2 to v1.45.1 (thunder-coding)
#40206 * update V8 to 9.4.146.19
(Micha��l Zasso) #40285 * tools
* update certdata.txt (Richard Lau)
#40280

Package Affected Version
pkg:rpm/fedora/nodejs?distro=fedora-35 < 16.11.1.1.fc35
Source # ID Name URL
Bugzilla 2014059 Bug #2014059 - CVE-2021-22960 llhttp: HTTP Request Smuggling when parsing the body https://bugzilla.redhat.com/show_bug.cgi?id=2014059
Bugzilla 2014057 Bug #2014057 - CVE-2021-22959 llhttp: HTTP Request Smuggling due to spaced in headers https://bugzilla.redhat.com/show_bug.cgi?id=2014057
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/fedora/nodejs?distro=fedora-35 fedora nodejs < 16.11.1.1.fc35 fedora-35
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...