CVE-2024-27982 log

Source
Severity Medium
Remote Yes
Type Insufficient validation
Description
The team has identified a vulnerability in the http server of the most recent version of Node, where malformed headers can lead to HTTP request smuggling. Specifically, if a space is placed before a content-length header, it is not interpreted correctly, enabling attackers to smuggle in a second request within the body of the first.

Impacts: This vulnerability affects all users in all active release lines: 18.x, 20.x and, 21.x.
Group Package Affected Fixed Severity Status Ticket
AVG-2854 nodejs-lts-hydrogen 18.18.2-2 18.20.1-1 High Vulnerable
AVG-2853 nodejs-lts-iron 20.11.1-1 20.12.1-1 High Fixed
AVG-2852 nodejs 21.7.1-1 21.7.2-1 High Fixed
References
https://nodejs.org/en/blog/vulnerability/april-2024-security-releases/#http-request-smuggling-via-content-length-obfuscation---cve-2024-27982---medium
https://github.com/nodejs/node/commit/1a65e98e22
https://github.com/nodejs/node/commit/5e34540a96
https://github.com/nodejs/node/commit/5d4d5848cf
Notes
This vulnerability affects all users in all active release lines: 18.x, 20.x and, 21.x.