[FREEBSD:A9C5E89D-2D15-11EC-8363-0022489AD614] Node.js -- October 2021 Security Releases

Severity Medium
Affected Packages 2
CVEs 2

Node.js reports:

  HTTP Request Smuggling due to spaced in headers (Medium)(CVE-2021-22959)
  The http parser accepts requests with a space (SP) right after the header name before the colon. This can lead to HTTP Request Smuggling (HRS).
  HTTP Request Smuggling when parsing the body (Medium)(CVE-2021-22960)
  The parse ignores chunk extensions when parsing the body of chunked requests. This leads to HTTP Request Smuggling (HRS) under certain conditions.
Package Affected Version
pkg:freebsd/node14 < 14.18.1
pkg:freebsd/node < 16.11.1
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:freebsd/node14 node14 < 14.18.1
Affected pkg:freebsd/node node < 16.11.1
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...