VDB
CVE-2012-2330
CVE-2012-2330
PUBLISHED
CVSS 6.400000095367432 MEDIUM
The Update method in src/node_http_parser.cc in Node.js before 0.6.17 and 0.7 before 0.7.8 does not properly check the length of a string, which allows remote attackers to obtain sensitive information (request header contents) and possibly spoof HTTP headers via a zero length string.
EPSS 0.62% · 70.5th percentile
Risk Scores
CVSS 2.0
6.400000095367432
EPSS Score
0.62%
70.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| nodejs | nodejs | 0.7.0, 0.7.1, 0.7.2 |
Timeline
- Aug 13, 2012 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- https://github.com/joyent/node/commit/c9a231d url
- http://blog.nodejs.org/2012/05/04/version-0-6-17-stable/ url
- 49066 third-party-advisory
- https://github.com/joyent/node/commit/7b3fb22 url
- [oss-security] 20120508 CVE request: node.js <0.6.17/0.7.8 HTTP server information disclosure mailing-list
- [oss-security] 20120508 Re: CVE request: node.js <0.6.17/0.7.8 HTTP server information disclosure mailing-list
- https://support.f5.com/csp/article/K99038439?utm_source=f5support&%3Butm_medium=RSS url
- https://nvd.nist.gov/vuln/detail/CVE-2012-2330 advisory
- https://support.f5.com/csp/article/K99038439?utm_source=f5support&utm_medium=RSS url
- http://blog.nodejs.org/2012/05/04/version-0-6-17-stable url