[FREEBSD:A9C5E89D-2D15-11EC-8363-0022489AD614] Node.js -- October 2021 Security Releases
Severity
Medium
Affected Packages
2
CVEs
2
Node.js reports:
HTTP Request Smuggling due to spaced in headers (Medium)(CVE-2021-22959)
The http parser accepts requests with a space (SP) right after the header name before the colon. This can lead to HTTP Request Smuggling (HRS).
HTTP Request Smuggling when parsing the body (Medium)(CVE-2021-22960)
The parse ignores chunk extensions when parsing the body of chunked requests. This leads to HTTP Request Smuggling (HRS) under certain conditions.
Package | Affected Version |
---|---|
pkg:freebsd/node14 | < 14.18.1 |
pkg:freebsd/node | < 16.11.1 |
- ID
- FREEBSD:A9C5E89D-2D15-11EC-8363-0022489AD614
- Severity
- medium
- Severity from
- CVE-2021-22959
- URL
- http://vuxml.freebsd.org/freebsd/a9c5e89d-2d15-11ec-8363-0022489ad614.html
- Published
-
2021-10-12T00:00:00
(2 years ago) - Modified
-
2021-10-14T00:00:00
(2 years ago) - Rights
- FreeBSD VuXML Security Team
- Other Advisories
-
- ALPINE:CVE-2021-22959
- ALPINE:CVE-2021-22960
- ALSA-2021:5171
- ALSA-2022:0350
- ASA-202110-4
- DSA-5170-1
- ELSA-2021-5171
- ELSA-2022-0350
- FEDORA-2021-9807b754d9
- FEDORA-2021-9818cabe0d
- FEDORA-2021-cbad295a90
- GLSA-202405-29
- openSUSE-SU-2021:1552-1
- openSUSE-SU-2021:1574-1
- openSUSE-SU-2021:3940-1
- openSUSE-SU-2021:3964-1
- RHEA-2022:5139
- RHSA-2021:5171
- RHSA-2022:0350
- RLEA-2022:5139
- RLSA-2021:5171
- RLSA-2022:0350
- SUSE-SU-2021:3886-1
- SUSE-SU-2021:3940-1
- SUSE-SU-2021:3964-1
- SUSE-SU-2022:0101-1
- SUSE-SU-2022:2855-1
Source | # ID | Name | URL |
---|---|---|---|
FreeBSD VuXML | https://nodejs.org/en/blog/vulnerability/oct-2021-security-releases/ |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |