MGASA-2021-0592
Dashboard / Vulnerabilities / MGASA-2021-0592
MGASA-2021-0592
Summary: Updated nodejs packages fix security vulnerability
Details: HTTP Request Smuggling due to spaces in headers. The http parser accepts requests with a space (SP) right after the header name before the colon. This can lead to HTTP Request Smuggling (HRS). (CVE-2021-22959) HTTP Request Smuggling when parsing the body. The parse ignores chunk extensions when parsing the body of chunked requests. This leads to HTTP Request Smuggling (HRS) under certain conditions. (CVE-2021-22960)
References: https://advisories.mageia.org/MGASA-2021-0592.html, https://bugs.mageia.org/show_bug.cgi?id=29584, https://lists.fedoraproject.org/archives/list/[email protected]/thread/EUZYFCI7N4TFZSIGA7WGZ4Q7V3EK76GH/
Affected packages
Package
Name: nodejs
Purl: pkg:rpm/mageia/nodejs?arch=source&distro=mageia-8
Affected ranges
Type: ECOSYSTEM
Events:
