CVE-2016-5325
published 2016-10-10CVE-2016-5325: CRLF injection vulnerability in the ServerResponse#writeHead function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before…
PriorityP430medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
4.09%
89.7th percentile
CRLF injection vulnerability in the ServerResponse#writeHead function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the reason argument.
Affected
103 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nodejs | < nodejs 4.6.0~dfsg-1 (bookworm) | nodejs 4.6.0~dfsg-1 (bookworm) |
| nodejs | node.js | — | — |
| nodejs | node.js | — | — |
| nodejs | node.js | — | — |
| nodejs | node.js | — | — |
| nodejs | node.js | — | — |
| nodejs | node.js | — | — |
| nodejs | node.js | — | — |
| nodejs | node.js | — | — |
| nodejs | node.js | — | — |
| nodejs | node.js | — | — |
| nodejs | node.js | — | — |
| nodejs | node.js | — | — |
| nodejs | node.js | — | — |
| nodejs | node.js | — | — |
| nodejs | node.js | — | — |
| nodejs | node.js | — | — |
| nodejs | node.js | — | — |
| nodejs | node.js | — | — |
| nodejs | node.js | — | — |
| nodejs | node.js | — | — |
| nodejs | node.js | — | — |
| nodejs | node.js | — | — |
| nodejs | node.js | — | — |
| nodejs | node.js | — | — |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.1MEDIUM
vendor_debian6.1LOW
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qpf8-fqrf-8p2h: CRLF injection vulnerability in the ServerResponse#writeHead function in Node
ghsa_unreviewed·2022-05-14
CVE-2016-5325 [MEDIUM] CWE-113 GHSA-qpf8-fqrf-8p2h: CRLF injection vulnerability in the ServerResponse#writeHead function in Node
CRLF injection vulnerability in the ServerResponse#writeHead function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the reason argument.
OSV
CVE-2016-5325: CRLF injection vulnerability in the ServerResponse#writeHead function in Node
osv·2016-10-10·CVSS 6.1
CVE-2016-5325 [MEDIUM] CVE-2016-5325: CRLF injection vulnerability in the ServerResponse#writeHead function in Node
CRLF injection vulnerability in the ServerResponse#writeHead function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the reason argument.
Red Hat
nodejs: reason argument in ServerResponse#writeHead() not properly validated
vendor_redhat·2016-06-13·CVSS 6.1
CVE-2016-5325 [MEDIUM] nodejs: reason argument in ServerResponse#writeHead() not properly validated
nodejs: reason argument in ServerResponse#writeHead() not properly validated
CRLF injection vulnerability in the ServerResponse#writeHead function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the reason argument.
It was found that the reason argument in ServerResponse#writeHead() was not properly validated. A remote attacker could possibly use this flaw to conduct an HTTP response splitting attack via a specially-crafted HTTP request.
Package: nodejs (Red Hat Mobile Application Platform 4) - Not affected
Package: nodejs010-nodejs (Red Hat OpenShift Enterprise 2) - Will not fix
Package: nodejs010-nodejs (Red Hat Software Collections
Debian
CVE-2016-5325: nodejs - CRLF injection vulnerability in the ServerResponse#writeHead function in Node.js...
vendor_debian·2016·CVSS 6.1
CVE-2016-5325 [MEDIUM] CVE-2016-5325: nodejs - CRLF injection vulnerability in the ServerResponse#writeHead function in Node.js...
CRLF injection vulnerability in the ServerResponse#writeHead function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the reason argument.
Scope: local
bookworm: resolved (fixed in 4.6.0~dfsg-1)
bullseye: resolved (fixed in 4.6.0~dfsg-1)
forky: resolved (fixed in 4.6.0~dfsg-1)
sid: resolved (fixed in 4.6.0~dfsg-1)
trixie: resolved (fixed in 4.6.0~dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-5325 nodejs: HTTP processing security defect [epel-all]
bugzilla·2016-06-15·CVSS 6.1
CVE-2016-5325 [MEDIUM] CVE-2016-5325 nodejs: HTTP processing security defect [epel-all]
CVE-2016-5325 nodejs: HTTP processing security defect [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora E
Bugzilla
CVE-2016-5325 nodejs: HTTP processing security defect [fedora-all]
bugzilla·2016-06-15·CVSS 6.1
CVE-2016-5325 [MEDIUM] CVE-2016-5325 nodejs: HTTP processing security defect [fedora-all]
CVE-2016-5325 nodejs: HTTP processing security defect [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. Whi
Bugzilla
CVE-2016-5325 nodejs: reason argument in ServerResponse#writeHead() not properly validated
bugzilla·2016-06-15·CVSS 6.1
CVE-2016-5325 [MEDIUM] CVE-2016-5325 nodejs: reason argument in ServerResponse#writeHead() not properly validated
CVE-2016-5325 nodejs: reason argument in ServerResponse#writeHead() not properly validated
An unspecified low-severity Node.js HTTP processing vulnerability was found and
will be fixed in latest update. Details are currently embargoed until new
releases are available.
https://nodejs.org/en/blog/vulnerability/june-2016-security-releases/
Discussion:
Created nodejs tracking bugs for this issue:
Affects: fedora-all [bug 1346913]
Affects: epel-all [bug 1346914]
---
This issue is now public via September 2016 security releases:
CVE-2016-5325: reason argument in ServerResponse#writeHead() not properly validated
This is a low severity security defect that that may make HTTP response splitting possible under certain circumstances. If user-input is passed to the reason argument to writeHea
Bugzilla
CVE-2015-5325 jenkins: JNLP slaves not subject to slave-to-master access control (SECURITY-206)
bugzilla·2015-11-16·CVSS 6.8
CVE-2015-5325 [MEDIUM] CVE-2015-5325 jenkins: JNLP slaves not subject to slave-to-master access control (SECURITY-206)
CVE-2015-5325 jenkins: JNLP slaves not subject to slave-to-master access control (SECURITY-206)
The following flaw was found in Jenkins:
Slaves connecting via JNLP were not subject to the optional slave-to-master access control documented at http://jenkins-ci.org/security-144 (CVE-2014-3665).
This flaw allows to circumvent the major protection against less trusted node admins.
External References:
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2015-11-11
Discussion:
Fixed in Fedora in:
jenkins-1.609.3-3.fc22
jenkins-1.625.2-2.fc23
jenkins-1.625.2-2.fc24
---
This issue has been addressed in the following products:
RHEL 7 Version of OpenShift Enterprise 3.1
Via RHSA-2016:0070 https://access.redhat.com/errata/RHSA-2016:0070
---
This issue has been address
arXiv
VulRG: Multi-Level Explainable Vulnerability Patch Ranking for Complex Systems Using Graphs
arxiv_fulltext·2025-02-16
VulRG: Multi-Level Explainable Vulnerability Patch Ranking for Complex Systems Using Graphs
VulRG: Multi-Level Explainable Vulnerability Patch Ranking for Complex Systems Using Graphs
Yuning Jiang
[email protected]
0000-0003-4791-8452
National University of Singapore
Singapore
Nay Oo
[email protected]
NCS Cyber Special Ops R&D
Singapore
Qiaoran Meng
[email protected]
National University of Singapore
Singapore
Hoon Wei Lim
[email protected]
NCS Cyber Special Ops R&D
Singapore
Biplab Sikdar
[email protected]
National University of Singapore
Singapore
Jiang et al.
## Abstract
As interconnected systems proliferate, safeguarding complex infrastructures against an escalating array of cyber threats has become an urgent challenge. The growing number of vulnerabilities, coupled with resource constraints, makes addressing every vulnerability impractical, thereby rende
http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00013.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0002.htmlhttp://www.securityfocus.com/bid/93483https://access.redhat.com/errata/RHSA-2016:2101https://github.com/nodejs/node/commit/c0f13e56a20f9bde5a67d873a7f9564487160762https://nodejs.org/en/blog/vulnerability/september-2016-security-releases/https://security.gentoo.org/glsa/201612-43http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00013.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0002.htmlhttp://www.securityfocus.com/bid/93483https://access.redhat.com/errata/RHSA-2016:2101https://github.com/nodejs/node/commit/c0f13e56a20f9bde5a67d873a7f9564487160762https://nodejs.org/en/blog/vulnerability/september-2016-security-releases/https://security.gentoo.org/glsa/201612-43
2016-10-10
Published