SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-8287

Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 allow two copies of a header field in an HTTP request (for example, two Transfer-Encoding header fields).

MEDIUM 6.5EPSS 16.3%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 16.3%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.

Description

Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 allow two copies of a header field in an HTTP request (for example, two Transfer-Encoding header fields). In this case, Node.js identifies the first header field and ignores the second. This can lead to HTTP Request Smuggling.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS
16.30% probability · 97th percentile
CISA KEV
Not listed
Weakness
CWE-444
Affected
nodejs/node.js · debian/debian linux · fedoraproject/fedora · oracle/graalvm · siemens/sinec infrastructure network services
Source
support@hackerone.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.