Lucene search

K
f5F5F5:K15311661
HistorySep 23, 2016 - 12:00 a.m.

K15311661 : NodeJS vulnerability CVE-2016-2086

2016-09-2300:00:00
my.f5.com
47

7.2 High

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

77.0%

Security Advisory Description

Node.js 0.10.x before 0.10.42, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allow remote attackers to conduct HTTP request smuggling attacks via a crafted Content-Length HTTP header. (CVE-2016-2086)
Impact
An attacker may be able to perform HTTP request smuggling by using a spoofed Content-Length header. For more information about HTTP request smuggling, refer toSection 9.5 Request Smugglingof Internet Engineering Task Force (RFC 7230).Note: This link takes you to a resource outside of AskF5. The third party could remove the document without our knowledge.

7.2 High

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

77.0%