CVE-2018-12116

Description

Node.js: All versions prior to Node.js 6.15.0 and 8.14.0: HTTP request splitting: If Node.js can be convinced to use unsanitized user-provided Unicode data for the path option of an HTTP request, then data can be provided which will trigger a second, unexpected, and user-defined HTTP request to made to the same server.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
0.576

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities are fixed in Node.js (11.15.0)Windows
Multiple vulnerabilities are fixed in Node.js (x64)(11.15.0)Windows
Multiple vulnerabilities are fixed in Node.js 10 (10.24.1)Windows
Multiple vulnerabilities are fixed in Node.js 16 (x64) (16.15.0)Windows
Multiple vulnerabilities are fixed in Node.js 16 (16.15.0)Windows
Multiple vulnerabilities are fixed in Node.js 10 (x64) (10.24.1)Windows
Multiple vulnerabilities are fixed in Node.js 8 8.14.0Windows
Multiple vulnerabilities are fixed in Node.js 8 (x64) 8.14.0Windows
Multiple Vulnerabilities are affected in IBM Planning Analytics Local 2.0Windows
CVE-2018-12116NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-309917Node.js (11.15.0)
PATCH-309918Node.js (x64)(11.15.0)
PATCH-319042Node.js 10 (10.24.1)
PATCH-332182Node.js 16 (x64) (16.20.2)
PATCH-332181Node.js 16 (16.20.2)
PATCH-319043Node.js 10 (x64) (10.24.1)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234