CVE-2018-12116 (node.js, suse_enterprise_storage, suse_linux_enterprise_server, suse_openstack_cloud)
-
Node.js: All versions prior to Node.js 6.15.0 and 8.14.0: HTTP request splitting: If Node.js can be convinced to use unsanitized user-provided Unicode data for the `path` option of an HTTP request, then data can be provided which will trigger a second, unexpected, and user-defined HTTP request to made to the same server.
https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-12116
© Lightnetics 2024