Vulnerability CVE-2019-15606: Information

Description

Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons

Severity: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Published: Feb. 7, 2020
Modified: March 8, 2024

Fixed packages

References to Advisories, Solutions, and Tools

Hyperlink
Resource
https://nodejs.org/en/blog/release/v13.8.0/
  • Vendor Advisory
https://hackerone.com/reports/730779
  • Exploit
  • Third Party Advisory
https://nodejs.org/en/blog/vulnerability/february-2020-security-releases/
  • Vendor Advisory
https://nodejs.org/en/blog/release/v10.19.0/
  • Release Notes
  • Vendor Advisory
https://nodejs.org/en/blog/release/v12.15.0/
  • Release Notes
  • Vendor Advisory
RHSA-2020:0573
  • Third Party Advisory
https://security.netapp.com/advisory/ntap-20200221-0004/
  • Third Party Advisory
RHSA-2020:0579
  • Third Party Advisory
RHSA-2020:0598
  • Third Party Advisory
RHSA-2020:0597
  • Third Party Advisory
RHSA-2020:0602
  • Third Party Advisory
openSUSE-SU-2020:0293
  • Mailing List
  • Third Party Advisory
GLSA-202003-48
  • Third Party Advisory
N/A
  • Third Party Advisory
DSA-4669
  • Third Party Advisory
N/A
  • Third Party Advisory
    1. Configuration 1

      cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:*
      Start including
      12.0.0
      End excliding
      12.15.0

      cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:*
      Start including
      10.0.0
      End excliding
      10.19.0

      cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:*
      Start including
      13.0.0
      End excliding
      13.8.0

      Configuration 2

      cpe:2.3:a:oracle:graalvm:20.0.0:*:*:*:enterprise:*:*:*

      cpe:2.3:a:oracle:graalvm:19.3.1:*:*:*:enterprise:*:*:*

      cpe:2.3:a:oracle:communications_cloud_native_core_network_function_cloud_native_environment:1.4.0:*:*:*:*:*:*:*

      Configuration 3

      cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

      Configuration 4

      cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_eus:8.1:*:*:*:*:*:*:*

      Configuration 5

      cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*