Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2022-35256

Published: August 31, 2023Last modified: August 31, 2023

Description

The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling.

Severity score breakdown

ParameterValue
Base score6.5
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityLOW
Integrity impactLOW
Availability impactNONE
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSnodejsNot affected (18.17.1-r0)
StreamnodejsNot affected (18.17.1-r0)

References

ON THIS PAGE