CVE-2024-27982
nodejs: HTTP Request Smuggling via Content Length Obfuscation
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The team has identified a critical vulnerability in the http server of the most recent version of Node, where malformed headers can lead to HTTP request smuggling. Specifically, if a space is placed before a content-length header, it is not interpreted correctly, enabling attackers to smuggle in a second request within the body of the first.
El equipo ha identificado una vulnerabilidad crítica en el servidor http de la versión más reciente de Node, donde los encabezados con formato incorrecto pueden provocar el contrabando de solicitudes HTTP. Específicamente, si se coloca un espacio antes de un encabezado de longitud de contenido, no se interpreta correctamente, lo que permite a los atacantes introducir de contrabando una segunda solicitud dentro del cuerpo de la primera.
An HTTP Request Smuggling vulnerability was found in Node.js due to Content-Length Obfuscation in the HTTP server. Malformed headers, particularly if a space is inserted before a content-length header, can result in HTTP request smuggling. This flaw allows attackers to inject a second request within the body of the first and poison web caches, bypass web application firewalls, and execute Cross-site scripting (XSS) attacks.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2024-02-29 CVE Reserved
- 2024-05-07 CVE Published
- 2024-05-08 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://hackerone.com/reports/2237099 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://access.redhat.com/security/cve/CVE-2024-27982 | 2024-07-16 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2275392 | 2024-07-16 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Node.js Search vendor "Node.js" | Node Search vendor "Node.js" for product "Node" | 20.12.0 Search vendor "Node.js" for product "Node" and version "20.12.0" | en |
Affected
| ||||||
Node.js Search vendor "Node.js" | Node Search vendor "Node.js" for product "Node" | 21.7.2 Search vendor "Node.js" for product "Node" and version "21.7.2" | en |
Affected
| ||||||
Node.js Search vendor "Node.js" | Node Search vendor "Node.js" for product "Node" | 18.20.0 Search vendor "Node.js" for product "Node" and version "18.20.0" | en |
Affected
|