Back to search
CVE-2019-15606
Published: Feb 7, 2020
Modified: Apr 30, 2025
PUBLISHED
Description
Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons
| Vendor | Product | Versions |
|---|---|---|
NodeJS | Node | affected 4.0 - < 4.*affected 5.0 - < 5.*affected 6.0 - < 6.*affected 7.0 - < 7.*affected 8.0 - < 8.*+5 more versions |
Weaknesses (CWE)
References
RHSA-2020:0573
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0579
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0597
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0598
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0602
vendor-advisory
x_refsource_REDHAT
openSUSE-SU-2020:0293
vendor-advisory
x_refsource_SUSE
GLSA-202003-48
vendor-advisory
x_refsource_GENTOO
DSA-4669
vendor-advisory
x_refsource_DEBIAN
https://www.oracle.com/security-alerts/cpuapr2020.html
x_refsource_MISC
https://www.oracle.com//security-alerts/cpujul2021.html
x_refsource_MISC
https://nodejs.org/en/blog/release/v13.8.0/
x_refsource_CONFIRM
https://nodejs.org/en/blog/vulnerability/february-2020-security-releases/
x_refsource_CONFIRM
https://nodejs.org/en/blog/release/v10.19.0/
x_refsource_CONFIRM
https://nodejs.org/en/blog/release/v12.15.0/
x_refsource_CONFIRM
https://security.netapp.com/advisory/ntap-20200221-0004/
x_refsource_CONFIRM
https://hackerone.com/reports/730779
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now