MGASA-2021-0592

Source
https://advisories.mageia.org/MGASA-2021-0592.html
Import Source
https://advisories.mageia.org/MGASA-2021-0592.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2021-0592
Related
Published
2021-12-30T16:41:51Z
Modified
2021-12-30T16:05:17Z
Summary
Updated nodejs packages fix security vulnerability
Details

HTTP Request Smuggling due to spaces in headers. The http parser accepts requests with a space (SP) right after the header name before the colon. This can lead to HTTP Request Smuggling (HRS). (CVE-2021-22959) HTTP Request Smuggling when parsing the body. The parse ignores chunk extensions when parsing the body of chunked requests. This leads to HTTP Request Smuggling (HRS) under certain conditions. (CVE-2021-22960)

References
Credits

Affected packages

Mageia:8 / nodejs

Package

Name
nodejs
Purl
pkg:rpm/mageia/nodejs?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
14.18.1-1.1.mga8

Ecosystem specific

{
    "section": "core"
}