The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS).
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
History
19 Jul 2023, 00:56
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:stormshield:stormshield_management_center:*:*:*:*:*:*:*:* |
23 Feb 2023, 16:32
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* cpe:2.3:a:siemens:sinec_ins:1.0:-:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:* cpe:2.3:a:siemens:sinec_ins:1.0:sp2:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* cpe:2.3:a:siemens:sinec_ins:1.0:sp1:*:*:*:*:*:* |
|
References |
|
|
References | (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2ICG6CSIB3GUWH5DUSQEVX53MOJW7LYK/ - Mailing List, Third Party Advisory | |
References | (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VMQK5L5SBYD47QQZ67LEMHNQ662GH3OY/ - Mailing List, Third Party Advisory | |
References | (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QCNN3YG2BCLS4ZEKJ3CLSUT6AS7AXTH3/ - Mailing List, Third Party Advisory |
29 Nov 2022, 04:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
23 Nov 2022, 14:43
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
07 Oct 2022, 16:39
Type | Values Removed | Values Added |
---|---|---|
Summary | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS). | |
References |
|
|
16 Sep 2022, 19:51
Type | Values Removed | Values Added |
---|---|---|
References | (CONFIRM) https://security.netapp.com/advisory/ntap-20220915-0001/ - Third Party Advisory |
15 Sep 2022, 18:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
27 Jul 2022, 15:57
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:* cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* |
21 Jul 2022, 15:14
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://nodejs.org/en/blog/vulnerability/july-2022-security-releases/ - Patch, Vendor Advisory | |
CWE | CWE-444 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.1 |
CPE | cpe:2.3:a:llhttp:llhttp:*:*:*:*:*:node.js:*:* cpe:2.3:a:nodejs:node.js:*:*:*:*:*:*:*:* |
14 Jul 2022, 15:19
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-07-14 15:15
Updated : 2024-02-04 22:51
NVD link : CVE-2022-32213
Mitre link : CVE-2022-32213
CVE.ORG link : CVE-2022-32213
JSON object : View
Products Affected
llhttp
- llhttp
debian
- debian_linux
nodejs
- node.js
siemens
- sinec_ins
fedoraproject
- fedora
stormshield
- stormshield_management_center
CWE
CWE-444
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')