[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2016-2216Date: (C)2016-04-28   (M)2024-04-17


The HTTP header parsing code in Node.js 0.10.x before 0.10.42, 0.11.6 through 0.11.16, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allows remote attackers to bypass an HTTP response-splitting protection mechanism via UTF-8 encoded Unicode characters in the HTTP header, as demonstrated by %c4%8d%c4%8a.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 7.5CVSS Score : 4.3
Exploit Score: 3.9Exploit Score: 8.6
Impact Score: 3.6Impact Score: 2.9
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: NETWORKAccess Vector: NETWORK
Attack Complexity: LOWAccess Complexity: MEDIUM
Privileges Required: NONEAuthentication: NONE
User Interaction: NONEConfidentiality: NONE
Scope: UNCHANGEDIntegrity: PARTIAL
Confidentiality: NONEAvailability: NONE
Integrity: HIGH 
Availability: NONE 
  
Reference:
BID-83141
FEDORA-2016-3102c11757
FEDORA-2016-8925b6119f
GLSA-201612-43
http://blog.safebreach.com/2016/02/09/http-response-splitting-in-node-js-root-cause-analysis/
http://info.safebreach.com/hubfs/Node-js-Response-Splitting.pdf
http://packetstormsecurity.com/files/135711/Node.js-HTTP-Response-Splitting.html
https://nodejs.org/en/blog/vulnerability/february-2016-security-releases/

CPE    17
cpe:/a:nodejs:node.js:0.10.18
cpe:/o:fedoraproject:fedora:22
cpe:/o:fedoraproject:fedora:23
cpe:/a:nodejs:node.js:4.2.2
...
CWE    1
CWE-20
OVAL    6
oval:org.secpod.oval:def:1900785
oval:org.secpod.oval:def:89043994
oval:org.secpod.oval:def:37854
oval:org.secpod.oval:def:110143
...

© SecPod Technologies