First published: Thu Apr 07 2016(Updated: )
The HTTP header parsing code in Node.js 0.10.x before 0.10.42, 0.11.6 through 0.11.16, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allows remote attackers to bypass an HTTP response-splitting protection mechanism via UTF-8 encoded Unicode characters in the HTTP header, as demonstrated by %c4%8d%c4%8a.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nodejs Node.js | =0.10.0 | |
Nodejs Node.js | =0.10.1 | |
Nodejs Node.js | =0.10.2 | |
Nodejs Node.js | =0.10.3 | |
Nodejs Node.js | =0.10.4 | |
Nodejs Node.js | =0.10.5 | |
Nodejs Node.js | =0.10.6 | |
Nodejs Node.js | =0.10.7 | |
Nodejs Node.js | =0.10.8 | |
Nodejs Node.js | =0.10.9 | |
Nodejs Node.js | =0.10.10 | |
Nodejs Node.js | =0.10.11 | |
Nodejs Node.js | =0.10.12 | |
Nodejs Node.js | =0.10.13 | |
Nodejs Node.js | =0.10.14 | |
Nodejs Node.js | =0.10.15 | |
Nodejs Node.js | =0.10.16 | |
Nodejs Node.js | =0.10.16-isaacs-manual | |
Nodejs Node.js | =0.10.17 | |
Nodejs Node.js | =0.10.18 | |
Nodejs Node.js | =0.10.19 | |
Nodejs Node.js | =0.10.20 | |
Nodejs Node.js | =0.10.21 | |
Nodejs Node.js | =0.10.22 | |
Nodejs Node.js | =0.10.23 | |
Nodejs Node.js | =0.10.24 | |
Nodejs Node.js | =0.10.25 | |
Nodejs Node.js | =0.10.26 | |
Nodejs Node.js | =0.10.27 | |
Nodejs Node.js | =0.10.28 | |
Nodejs Node.js | =0.10.29 | |
Nodejs Node.js | =0.10.30 | |
Nodejs Node.js | =0.10.31 | |
Nodejs Node.js | =0.10.32 | |
Nodejs Node.js | =0.10.33 | |
Nodejs Node.js | =0.10.34 | |
Nodejs Node.js | =0.10.35 | |
Nodejs Node.js | =0.10.36 | |
Nodejs Node.js | =0.10.37 | |
Nodejs Node.js | =0.10.38 | |
Nodejs Node.js | =0.10.39 | |
Nodejs Node.js | =0.10.40 | |
Nodejs Node.js | =0.10.41 | |
Nodejs Node.js | =0.11.6 | |
Nodejs Node.js | =0.11.7 | |
Nodejs Node.js | =0.11.8 | |
Nodejs Node.js | =0.11.9 | |
Nodejs Node.js | =0.11.10 | |
Nodejs Node.js | =0.11.11 | |
Nodejs Node.js | =0.11.12 | |
Nodejs Node.js | =0.11.13 | |
Nodejs Node.js | =0.11.14 | |
Nodejs Node.js | =0.11.15 | |
Nodejs Node.js | =0.11.16 | |
Nodejs Node.js | =0.12.0 | |
Nodejs Node.js | =0.12.1 | |
Nodejs Node.js | =0.12.2 | |
Nodejs Node.js | =0.12.3 | |
Nodejs Node.js | =0.12.4 | |
Nodejs Node.js | =0.12.5 | |
Nodejs Node.js | =0.12.6 | |
Nodejs Node.js | =0.12.7 | |
Nodejs Node.js | =0.12.8 | |
Nodejs Node.js | =0.12.9 | |
Nodejs Node.js | =4.0.0 | |
Nodejs Node.js | =4.1.0 | |
Nodejs Node.js | =4.1.1 | |
Nodejs Node.js | =4.1.2 | |
Nodejs Node.js | =4.2.0 | |
Nodejs Node.js | =4.2.1 | |
Nodejs Node.js | =4.2.2 | |
Nodejs Node.js | =4.2.3 | |
Nodejs Node.js | =4.2.4 | |
Nodejs Node.js | =4.2.5 | |
Nodejs Node.js | =4.2.6 | |
Nodejs Node.js | =5.0.0 | |
Nodejs Node.js | =5.1.0 | |
Nodejs Node.js | =5.1.1 | |
Nodejs Node.js | =5.2.0 | |
Nodejs Node.js | =5.3.0 | |
Nodejs Node.js | =5.4.0 | |
Nodejs Node.js | =5.4.1 | |
Nodejs Node.js | =5.5.0 | |
Fedoraproject Fedora | =22 | |
Fedoraproject Fedora | =23 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.