Lucene search

K
f5F5F5:K23134279
HistoryMar 20, 2017 - 12:00 a.m.

K23134279 : Node.js vulnerability CVE-2016-2216

2017-03-2000:00:00
my.f5.com
19

7.5 High

AI Score

Confidence

High

0.007 Low

EPSS

Percentile

79.9%

Security Advisory Description

The HTTP header parsing code in Node.js 0.10.x before 0.10.42, 0.11.6 through 0.11.16, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allows remote attackers to bypass an HTTP response-splitting protection mechanism via UTF-8 encoded Unicode characters in the HTTP header, as demonstrated by %c4%8d%c4%8a. (CVE-2016-2216)
Impact
This vulnerability may allow a remote attacker to bypass an HTTP response-splitting protection mechanism.

7.5 High

AI Score

Confidence

High

0.007 Low

EPSS

Percentile

79.9%