CVE-2019-15606

Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons
References
Link Resource
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00008.html Mailing List Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0573 Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0579 Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0597 Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0598 Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0602 Third Party Advisory
https://hackerone.com/reports/730779 Exploit Third Party Advisory
https://nodejs.org/en/blog/release/v10.19.0/ Release Notes Vendor Advisory
https://nodejs.org/en/blog/release/v12.15.0/ Release Notes Vendor Advisory
https://nodejs.org/en/blog/release/v13.8.0/ Vendor Advisory
https://nodejs.org/en/blog/vulnerability/february-2020-security-releases/ Vendor Advisory
https://security.gentoo.org/glsa/202003-48 Third Party Advisory
https://security.netapp.com/advisory/ntap-20200221-0004/ Third Party Advisory
https://www.debian.org/security/2020/dsa-4669 Third Party Advisory
https://www.oracle.com//security-alerts/cpujul2021.html Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2020.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00008.html Mailing List Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0573 Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0579 Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0597 Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0598 Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0602 Third Party Advisory
https://hackerone.com/reports/730779 Exploit Third Party Advisory
https://nodejs.org/en/blog/release/v10.19.0/ Release Notes Vendor Advisory
https://nodejs.org/en/blog/release/v12.15.0/ Release Notes Vendor Advisory
https://nodejs.org/en/blog/release/v13.8.0/ Vendor Advisory
https://nodejs.org/en/blog/vulnerability/february-2020-security-releases/ Vendor Advisory
https://security.gentoo.org/glsa/202003-48 Third Party Advisory
https://security.netapp.com/advisory/ntap-20200221-0004/ Third Party Advisory
https://www.debian.org/security/2020/dsa-4669 Third Party Advisory
https://www.oracle.com//security-alerts/cpujul2021.html Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2020.html Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:*
cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:*
cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:oracle:communications_cloud_native_core_network_function_cloud_native_environment:1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:graalvm:19.3.1:*:*:*:enterprise:*:*:*
cpe:2.3:a:oracle:graalvm:20.0.0:*:*:*:enterprise:*:*:*

Configuration 3 (hide)

cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:8.1:*:*:*:*:*:*:*

Configuration 5 (hide)

cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2020-02-07 15:15

Updated : 2024-11-21 04:29


NVD link : CVE-2019-15606

Mitre link : CVE-2019-15606

CVE.ORG link : CVE-2019-15606


JSON object : View

Products Affected

oracle

  • communications_cloud_native_core_network_function_cloud_native_environment
  • graalvm

debian

  • debian_linux

nodejs

  • node.js

redhat

  • enterprise_linux_eus
  • enterprise_linux

opensuse

  • leap
CWE
CWE-20

Improper Input Validation

NVD-CWE-Other