Lucene search

K
ibmIBM2ECA4222DEDB4E4A04241685461C605ABC21EC9265B95A4216ABEB9987022E9D
HistoryJan 04, 2022 - 1:01 p.m.

Security Bulletin: Vulnerability in Node.js affects IBM Event Streams (CVE-2021-22959)

2022-01-0413:01:18
www.ibm.com
12
node.js
ibm event streams
vulnerability
http request smuggling
cve-2021-22959
ibm fix central
upgrade
web cache
xss attacks
helm-based releases
continuous delivery
extended update support

EPSS

0.005

Percentile

76.3%

Summary

There is a vulnerability in the Node.js open source runtime. The runtime is used by the IBM Event Streams. The CVE has been addressed.

Vulnerability Details

CVEID:CVE-2021-22959
**DESCRIPTION:**Node.js is vulnerable to HTTP request smuggling, caused by an error related to a space in headers. A remote attacker could send a specially-crafted request with a space (SP) right after the header name before the colon to lead to HTTP Request Smuggling (HRS). An attacker could exploit this vulnerability to poison the web cache, bypass web application firewall protection, and conduct XSS attacks.
CVSS Base score: 6.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/211168 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Event Streams 2019.4.1, 2019.4.2, 2019.4.3, 2019.4.4
IBM Event Streams 10.0.0, 10.1.0, 10.2.0, 10.3.0, 10.3.1, 10.4.0

Remediation/Fixes

IBM Event Streams (Helm-based releases)

IBM Event Streams (Continuous Delivery)

IBM Event Streams (Extended Update Support)

Workarounds and Mitigations

None