CVE-2016-2216 (High) detected in https://source.codeaurora.org/quic/le/platform/external/node/jenkins-accept-commit-temp2 - autoclosed #205
Labels
Mend: dependency security vulnerability
Security vulnerability detected by WhiteSource
CVE-2016-2216 - High Severity Vulnerability
Library home page: https://source.codeaurora.org/quic/le/platform/external/node/
Found in base branch: archived-io.js-v0.10
The HTTP header parsing code in Node.js 0.10.x before 0.10.42, 0.11.6 through 0.11.16, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allows remote attackers to bypass an HTTP response-splitting protection mechanism via UTF-8 encoded Unicode characters in the HTTP header, as demonstrated by %c4%8d%c4%8a.
Publish Date: 2016-04-07
URL: CVE-2016-2216
Base Score Metrics:
Type: Upgrade version
Origin: https://nodejs.org/en/blog/vulnerability/february-2016-security-releases/
Release Date: 2016-04-07
Fix Resolution: 0.10.42,0.12.10,4.3.0,5.6.0
Step up your Open Source Security Game with WhiteSource here
The text was updated successfully, but these errors were encountered: