cbcvebase.
CVE-2019-15606
published 2020-02-07

CVE-2019-15606: Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debiannodejs< nodejs 10.19.0~dfsg-1 (bookworm)nodejs 10.19.0~dfsg-1 (bookworm)
nodejsnode>= 10.0 < 10.19.010.19.0
nodejsnode>= 11.0 < 11.*11.*
nodejsnode>= 12.0 < 12.15.012.15.0
nodejsnode>= 13.0 < 13.8.013.8.0
nodejsnode>= 4.0 < 4.*4.*
nodejsnode>= 5.0 < 5.*5.*
nodejsnode>= 6.0 < 6.*6.*
nodejsnode>= 7.0 < 7.*7.*
nodejsnode>= 8.0 < 8.*8.*
nodejsnode>= 9.0 < 9.*9.*
nodejsnode.js>= 10.0.0 < 10.19.010.19.0
nodejsnode.js>= 12.0.0 < 12.15.012.15.0
nodejsnode.js>= 13.0.0 < 13.8.013.8.0
nodejsnodejs>= 0 < 10.19.0~dfsg-110.19.0~dfsg-1
nodejsnodejs>= 0 < 10.19.0~dfsg-110.19.0~dfsg-1
nodejsnodejs>= 0 < 10.19.0~dfsg-110.19.0~dfsg-1
nodejsnodejs>= 0 < 10.19.0~dfsg-110.19.0~dfsg-1
nodejsnodejs>= 0 < 10.19.0~dfsg-3ubuntu1.110.19.0~dfsg-3ubuntu1.1
nodejsnodejs>= 0 < 4.2.6~dfsg-1ubuntu4.2+esm24.2.6~dfsg-1ubuntu4.2+esm2
nodejsnodejs>= 0 < 8.10.0~dfsg-2ubuntu0.4+esm28.10.0~dfsg-2ubuntu0.4+esm2
opensuseleap
oraclecommunications_cloud_native_core_network_function_cloud_native_environment
oraclegraalvm

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL