CVE Database
/

CVE-2019-15606

Back to search

CVE-2019-15606

Published: Feb 7, 2020

Modified: Apr 30, 2025

PUBLISHED

Description

Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons

VendorProductVersions

NodeJS

Node

affected
4.0 - < 4.*
affected
5.0 - < 5.*
affected
6.0 - < 6.*
affected
7.0 - < 7.*
affected
8.0 - < 8.*

+5 more versions

Weaknesses (CWE)

References

RHSA-2020:0573
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0579
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0597
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0598
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0602
vendor-advisory
x_refsource_REDHAT
openSUSE-SU-2020:0293
vendor-advisory
x_refsource_SUSE
GLSA-202003-48
vendor-advisory
x_refsource_GENTOO
DSA-4669
vendor-advisory
x_refsource_DEBIAN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now