Skip to content

Commit a595c40

Browse files
vuln: add vulnerabilities from april security release (#1272)
1 parent f538ab7 commit a595c40

File tree

2 files changed

+24
-0
lines changed

2 files changed

+24
-0
lines changed

vuln/core/139.json

+12
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
{
2+
"cve": [
3+
"CVE-2024-27983"
4+
],
5+
"vulnerable": "18.x || 20.x || 21.x",
6+
"patched": "^18.20.1 || ^20.12.1 || ^21.7.2",
7+
"ref": "https://nodejs.org/en/blog/vulnerability/april-2024-security-releases/",
8+
"overview": "An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets with a few HTTP/2 frames inside. It is possible to leave some data in nghttp2 memory after reset when headers with HTTP/2 CONTINUATION frame are sent to the server and then a TCP connection is abruptly closed by the client triggering the Http2Session destructor while header frames are still being processed (and stored in memory) causing a race condition.",
9+
"affectedEnvironments": [
10+
"all"
11+
]
12+
}

vuln/core/140.json

+12
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
{
2+
"cve": [
3+
"CVE-2024-27982"
4+
],
5+
"vulnerable": "18.x || 20.x || 21.x",
6+
"patched": "^18.20.1 || ^20.12.1 || ^21.7.2",
7+
"ref": "https://nodejs.org/en/blog/vulnerability/april-2024-security-releases/",
8+
"overview": "The team has identified a critical vulnerability in the http server of the most recent version of Node, where malformed headers can lead to HTTP request smuggling. Specifically, if a space is placed before a content-length header, it is not interpreted correctly, enabling attackers to smuggle in a second request within the body of the first.",
9+
"affectedEnvironments": [
10+
"all"
11+
]
12+
}

0 commit comments

Comments
 (0)