SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-15606

Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons

CRITICAL 9.8EPSS 20.0%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 20.0%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.

Description

Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
20.04% probability · 97th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
nodejs/node.js · oracle/communications cloud native core network function cloud native environment · oracle/graalvm · debian/debian linux · redhat/enterprise linux · redhat/enterprise linux eus · opensuse/leap
Source
support@hackerone.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.