UBUNTU-CVE-2022-32213
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-32213
UBUNTU-CVE-2022-32213
Summary:
Details: The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS).
References: https://ubuntu.com/security/CVE-2022-32213, https://nodejs.org/en/blog/vulnerability/july-2022-security-releases/#http-request-smuggling-flawed-parsing-of-transfer-encoding-medium-cve-2022-32213, https://github.com/nodejs/node/commit/da0fda0fe81d372e24c0cb11aec37534985708dd, https://github.com/nodejs/node/commit/d9b71f4c241fa31cc2a48331a4fc28c15937875a, https://ubuntu.com/security/notices/USN-6491-1, https://www.cve.org/CVERecord?id=CVE-2022-32213
Affected packages
Package
Name: nodejs
Purl: pkg:deb/ubuntu/[email protected]~dfsg-1ubuntu3.2?arch=source&distro=jammy
Affected ranges
Type: ECOSYSTEM
Events:
