CVE-2022-32215

6.5MEDIUM

The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding headers. This can lead to HTTP Request Smuggling (HRS).

Publicado: 7/14/2022Actualizado: 11/21/2024

Descripción

The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding headers. This can lead to HTTP Request Smuggling (HRS).

Análisis IAImpulsado por IA

Productos Afectados

llhttpllhttp
llhttpllhttp
llhttpllhttp
nodejsnode.js
nodejsnode.js
nodejsnode.js
nodejsnode.js
nodejsnode.js
fedoraprojectfedora
35
fedoraprojectfedora
36
fedoraprojectfedora
37
siemenssinec_ins
1.0
siemenssinec_ins
1.0
siemenssinec_ins
1.0
debiandebian_linux
11.0
stormshieldstormshield_management_center

Referencias