VulnerabilityModified
CVE-2019-15606
Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons
CRITICAL 9.8EPSS 20.0%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 20.0%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 20.04% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- nodejs/node.js · oracle/communications cloud native core network function cloud native environment · oracle/graalvm · debian/debian linux · redhat/enterprise linux · redhat/enterprise linux eus · opensuse/leap
- Source
- support@hackerone.com
References
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00008.htmlMailing List, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0573Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0579Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0597Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0598Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0602Third Party Advisory
- https://hackerone.com/reports/730779Exploit, Third Party Advisory
- https://nodejs.org/en/blog/release/v10.19.0/Release Notes, Vendor Advisory
- https://nodejs.org/en/blog/release/v12.15.0/Release Notes, Vendor Advisory
- https://nodejs.org/en/blog/release/v13.8.0/Vendor Advisory
- https://nodejs.org/en/blog/vulnerability/february-2020-security-releases/Vendor Advisory
- https://security.gentoo.org/glsa/202003-48Third Party Advisory
- https://security.netapp.com/advisory/ntap-20200221-0004/Third Party Advisory
- https://www.debian.org/security/2020/dsa-4669Third Party Advisory
- https://www.oracle.com//security-alerts/cpujul2021.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2020.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00008.htmlMailing List, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0573Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0579Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0597Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0598Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0602Third Party Advisory
- https://hackerone.com/reports/730779Exploit, Third Party Advisory
- https://nodejs.org/en/blog/release/v10.19.0/Release Notes, Vendor Advisory
- https://nodejs.org/en/blog/release/v12.15.0/Release Notes, Vendor Advisory
- https://nodejs.org/en/blog/release/v13.8.0/Vendor Advisory
- https://nodejs.org/en/blog/vulnerability/february-2020-security-releases/Vendor Advisory
- https://security.gentoo.org/glsa/202003-48Third Party Advisory
- https://security.netapp.com/advisory/ntap-20200221-0004/Third Party Advisory
- https://www.debian.org/security/2020/dsa-4669Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.