Red Hat Bugzilla – Bug 1561981
CVE-2018-7159 nodejs: HTTP parser allowed for spaces inside Content-Length header values
Last modified: 2018-10-04 04:56:17 EDT
The Node.js HTTP parser allowed for spaces inside Content-Length header values. Such values now lead to rejected connections in the same way as non-numeric values. References: https://github.com/nodejs/node/blob/master/doc/changelogs/CHANGELOG_V8.md
Created nodejs tracking bugs for this issue: Affects: fedora-all [bug 1562027] Affects: epel-all [bug 1562026]
Upstream fix: https://github.com/nodejs/node/commit/c39167dc26
NodeJS is only packaged as an ImageStream in Openshift Enterprise 3.9, which is a container image from RH Software Collections. Marking Openshift Enterprise as not affected.