CVE-2022-32213: XSS
Published Jul 8, 2022
·Updated
A vulnerability was found in NodeJS due to improper validation of HTTP requests. The llhttp parser in the http module does not correctly parse and validate Transfer-Encoding headers. This issue can lead to HTTP Request Smuggling (HRS), causing web cache poisoning, and conducting XSS attacks.
Affected Software
22 affected componentsFixes available
redhat/nodejs<1:16.16.0-1.el9_0
1:16.16.0-1.el9_0
redhat/rh-nodejs14-nodejs<0:14.20.0-2.el7
0:14.20.0-2.el7
debian/nodejs
10.24.0~dfsg-1~deb10u110.24.0~dfsg-1~deb10u312.22.12~dfsg-1~deb11u418.13.0+dfsg1-1
redhat/nodejs<14.20.0
14.20.0
redhat/nodejs<16.20.0
16.20.0
redhat/nodejs<18.5.0
18.5.0
IBM Cognos Controller<=11.0.0 - 11.0.1
llhttp Llhttp Node.js<2.1.5
llhttp Llhttp Node.js>=6.0.0<6.0.7
Nodejs Node.js>=14.0.0<=14.14.0
Nodejs Node.js>=14.15.0<14.20.1
Nodejs Node.js>=16.0.0<=16.12.0
Nodejs Node.js>=16.13.0<16.17.1
Nodejs Node.js>=18.0.0<18.9.1
Fedoraproject Fedora=35
Fedoraproject Fedora=36
Fedoraproject Fedora=37
Siemens Sinec Ins=1.0
Siemens Sinec Ins=1.0-sp1
Siemens Sinec Ins=1.0-sp2
Debian Debian Linux=11.0
Stormshield Stormshield Management Center<3.3.2
Remediation
Event History
Jul 8, 2022
CVE Published
12:00 AM
Data Sourced
via Red Hat·06:47 PM
DescriptionSeverityAffected Software
Jul 14, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2022-32213?
CVE-2022-32213 is a vulnerability found in NodeJS due to improper validation of HTTP requests.
2
How does CVE-2022-32213 impact web applications?
CVE-2022-32213 can lead to HTTP Request Smuggling (HRS), causing web cache poisoning, and conducting XSS attacks.
3
What software versions are affected by CVE-2022-32213?
Versions of llhttp <v14.20.1, <v16.17.1, and <v18.9.1 in the http module in Node.js are affected.
4
What is the severity of CVE-2022-32213?
CVE-2022-32213 has a severity rating of 6.5 (medium).
5
How can I fix CVE-2022-32213?
To fix CVE-2022-32213, update Node.js to a version equal to or above v14.20.1, v16.17.1, or v18.9.1.