Description
Node.js: All versions prior to Node.js 6.15.0 and 8.14.0: HTTP request splitting: If Node.js can be convinced to use unsanitized user-provided Unicode data for the path option of an HTTP request, then data can be provided which will trigger a second, unexpected, and user-defined HTTP request to made to the same server.
Mitigation
Minimal update. May introduce new vulnerabilities or breaking changes.
|
 debian 12 | | | 10.15.0~dfsg-6 |
 debian 14 | | | 10.15.0~dfsg-6 |
 debian 13 | | | 10.15.0~dfsg-6 |
 debian 11 | | | 10.15.0~dfsg-6 |
 alpine v3.8 | | =4.4.3-r0 || =4.4.4-r0 || =4.4.5-r0 || =4.4.7-r0 || =4.5.0-r0 || =6.10.0-r0 || =6.10.1-r0 || =6.10.3-r0 || =6.11.0-r0 || =6.11.1-r0 || =6.11.1-r1 || =6.11.1-r2 || =6.11.2-r0 || =6.11.3-r0 || =6.11.4-r0 || =6.11.5-r0 || =6.9.1-r0 || =6.9.1-r1 || =6.9.2-r0 || =6.9.4-r0 || =6.9.4-r1 || =6.9.5-r0 || =6.9.5-r1 || =8.10.0-r0 || =8.11.0-r0 || =8.11.0-r1 || =8.11.1-r0 || =8.11.1-r1 || =8.11.1-r2 || =8.11.2-r0 || =8.11.3-r0 || =8.11.3-r1 || =8.11.4-r0 || =8.9.0-r0 || =8.9.1-r0 || =8.9.2-r0 || =8.9.3-r0 || =8.9.3-r1 || =8.9.4-r0 || >=0 <8.14.0-r0 | 8.14.0-r0 |
 npm | | >=6.0.0 <=6.8.1 || >=6.9.0 <6.15.0 || >=8.0.0 <=8.8.1 || >=8.9.0 <8.14.0 | 6.15.0, 8.14.0 |