The team has identified a critical vulnerability in the http server of the most recent version of Node, where malformed headers can lead to HTTP request smuggling. Specifically, if a space is placed before a content-length header, it is not interpreted correctly, enabling attackers to smuggle in a second request within the body of the first.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Red Hat Enterprise Linux 8 | RedHat | nodejs:20-8090020240422150739.a75119d5 | * |
Red Hat Enterprise Linux 8 | RedHat | nodejs:18-8090020240429131734.a75119d5 | * |
Red Hat Enterprise Linux 9 | RedHat | nodejs:18-9040020240422140329.rhel9 | * |
Red Hat Enterprise Linux 9 | RedHat | nodejs:20-9040020240419140200.rhel9 | * |
Red Hat Enterprise Linux 9 | RedHat | nodejs-1:16.20.2-8.el9_4 | * |
Red Hat Enterprise Linux 9.0 Extended Update Support | RedHat | nodejs-1:16.20.2-6.el9_0 | * |
Red Hat Enterprise Linux 9.2 Extended Update Support | RedHat | nodejs-1:16.20.2-6.el9_2.3 | * |
Nodejs | Ubuntu | mantic | * |
Nodejs | Ubuntu | trusty/esm | * |
Nodejs | Ubuntu | upstream | * |