summaryrefslogtreecommitdiffstats
path: root/data/CVE/list
diff options
context:
space:
mode:
authorSalvatore Bonaccorso <carnil@debian.org>2022-09-23 20:41:38 +0200
committerSalvatore Bonaccorso <carnil@debian.org>2022-09-23 20:41:38 +0200
commit8f703ce22c88ea5a7b327fdcfd6dfe1b99a5bce5 (patch)
tree5e966451f33f515a6a42116eb795f935c7e0d169 /data/CVE/list
parenta426131815ffda3e40f46ffe328814bd5ff4d0dc (diff)
Reference followup for CVE-2022-32215/nodejs
Diffstat (limited to 'data/CVE/list')
-rw-r--r--data/CVE/list1
1 files changed, 1 insertions, 0 deletions
diff --git a/data/CVE/list b/data/CVE/list
index 3ba044d07d..bc251f22fa 100644
--- a/data/CVE/list
+++ b/data/CVE/list
@@ -23572,6 +23572,7 @@ CVE-2022-32215 (The llhttp parser in the http module in Node v17.6.0 does not co
NOTE: https://nodejs.org/en/blog/vulnerability/july-2022-security-releases/#http-request-smuggling-incorrect-parsing-of-multi-line-transfer-encoding-medium-cve-2022-32215
NOTE: https://github.com/nodejs/node/commit/da0fda0fe81d372e24c0cb11aec37534985708dd (v14.x)
NOTE: https://github.com/nodejs/node/commit/d9b71f4c241fa31cc2a48331a4fc28c15937875a (main)
+ NOTE: https://nodejs.org/en/blog/vulnerability/september-2022-security-releases/#http-request-smuggling-due-to-incorrect-parsing-of-multi-line-transfer-encoding-medium-improper-fix-for-cve-2022-32215
CVE-2022-32214 (The llhttp parser in the http module in Node.js does not strictly use ...)
- nodejs 18.6.0+dfsg-3
[buster] - nodejs <not-affected> (llhttp dependency/embedding introduced in 12.x)

© 2014-2024 Faster IT GmbH | imprint | privacy policy