CVE-2019-15606
published 2020-02-07CVE-2019-15606: Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons
PriorityP263critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
20.04%
97.1th percentile
Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | nodejs | < nodejs 10.19.0~dfsg-1 (bookworm) | nodejs 10.19.0~dfsg-1 (bookworm) |
| nodejs | node | >= 10.0 < 10.19.0 | 10.19.0 |
| nodejs | node | >= 11.0 < 11.* | 11.* |
| nodejs | node | >= 12.0 < 12.15.0 | 12.15.0 |
| nodejs | node | >= 13.0 < 13.8.0 | 13.8.0 |
| nodejs | node | >= 4.0 < 4.* | 4.* |
| nodejs | node | >= 5.0 < 5.* | 5.* |
| nodejs | node | >= 6.0 < 6.* | 6.* |
| nodejs | node | >= 7.0 < 7.* | 7.* |
| nodejs | node | >= 8.0 < 8.* | 8.* |
| nodejs | node | >= 9.0 < 9.* | 9.* |
| nodejs | node.js | >= 10.0.0 < 10.19.0 | 10.19.0 |
| nodejs | node.js | >= 12.0.0 < 12.15.0 | 12.15.0 |
| nodejs | node.js | >= 13.0.0 < 13.8.0 | 13.8.0 |
| nodejs | nodejs | >= 0 < 10.19.0~dfsg-1 | 10.19.0~dfsg-1 |
| nodejs | nodejs | >= 0 < 10.19.0~dfsg-1 | 10.19.0~dfsg-1 |
| nodejs | nodejs | >= 0 < 10.19.0~dfsg-1 | 10.19.0~dfsg-1 |
| nodejs | nodejs | >= 0 < 10.19.0~dfsg-1 | 10.19.0~dfsg-1 |
| nodejs | nodejs | >= 0 < 10.19.0~dfsg-3ubuntu1.1 | 10.19.0~dfsg-3ubuntu1.1 |
| nodejs | nodejs | >= 0 < 4.2.6~dfsg-1ubuntu4.2+esm2 | 4.2.6~dfsg-1ubuntu4.2+esm2 |
| nodejs | nodejs | >= 0 < 8.10.0~dfsg-2ubuntu0.4+esm2 | 8.10.0~dfsg-2ubuntu0.4+esm2 |
| opensuse | leap | — | — |
| oracle | communications_cloud_native_core_network_function_cloud_native_environment | — | — |
| oracle | graalvm | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →HTTP header values containing trailing whitespace may be used to bypass authorization checks in Node.js — inspect incoming HTTP requests for header values with trailing optional whitespace (spaces/tabs) that could differ from what a Node.js server sees vs. an upstream proxy ↗
- →Look for HTTP(s) requests where header values include trailing whitespace that passes upstream proxy validation but is not stripped by the Node.js HTTP(s) server, enabling authorization bypass ↗
- ·Vulnerability affects Node.js versions 10, 12, and 13 only; fixed in 10.19.0, 12.15.0, and 13.8.0 — verify Node.js version before applying detection logic ↗
- ·Red Hat Quay 3 nodejs package is listed as Not Affected — scope detection efforts to confirmed affected Node.js deployments ↗
- ·The upstream HackerOne report detailing the exact exploitation technique is not yet public — full attack surface details may be incomplete ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Node.js vulnerabilities
vendor_ubuntu·2023-09-19·CVSS 7.5
CVE-2019-15604 [HIGH] Node.js vulnerabilities
Title: Node.js vulnerabilities
Summary: Several security issues were fixed in Node.js.
Rogier Schouten discovered that Node.js incorrectly handled certain inputs. If
a user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to cause a denial
of service. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
(CVE-2019-15604)
Ethan Rubinson discovered that Node.js incorrectly handled certain inputs. If
a user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to obtain
sensitive information. This issue only affected Ubuntu 16.04 LTS and
Ubuntu 18.04 LTS. (CVE-2019-15605)
Alyssa Wilk discovered that Node.js incorrectly handled
Oracle
Oracle Oracle GraalVM Risk Matrix: JavaScript (Node.js) — CVE-2019-15606
vendor_oracle·2020-04-15·CVSS 9.8
CVE-2019-15606 [CRITICAL] Oracle Oracle GraalVM Risk Matrix: JavaScript (Node.js) — CVE-2019-15606
Oracle Oracle GraalVM Risk Matrix: JavaScript (Node.js) vulnerability
CVE: CVE-2019-15606
CVSS: 9.8
Protocol: Multiple
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2020 (APR 2020)
Red Hat
nodejs: HTTP header values do not have trailing optional whitespace trimmed
vendor_redhat·2020-02-07·CVSS 9.8
CVE-2019-15606 [CRITICAL] CWE-138 nodejs: HTTP header values do not have trailing optional whitespace trimmed
nodejs: HTTP header values do not have trailing optional whitespace trimmed
Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons
A flaw was found in Node.js where the HTTP(s) header values were not stripped of trailing whitespace. An attacker can use this flaw to send an HTTP(s) request which is validated by an upstream proxy server, but not by the Node.js HTTP(s) server.
Package: nodejs (Red Hat Quay 3) - Not affected
Debian
CVE-2019-15606: nodejs - Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 ca...
vendor_debian·2019·CVSS 9.8
CVE-2019-15606 [CRITICAL] CVE-2019-15606: nodejs - Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 ca...
Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons
Scope: local
bookworm: resolved (fixed in 10.19.0~dfsg-1)
bullseye: resolved (fixed in 10.19.0~dfsg-1)
forky: resolved (fixed in 10.19.0~dfsg-1)
sid: resolved (fixed in 10.19.0~dfsg-1)
trixie: resolved (fixed in 10.19.0~dfsg-1)
OSV
nodejs vulnerabilities
osv·2023-09-19·CVSS 7.5
CVE-2019-15604 [HIGH] nodejs vulnerabilities
nodejs vulnerabilities
Rogier Schouten discovered that Node.js incorrectly handled certain inputs. If
a user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to cause a denial
of service. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
(CVE-2019-15604)
Ethan Rubinson discovered that Node.js incorrectly handled certain inputs. If
a user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to obtain
sensitive information. This issue only affected Ubuntu 16.04 LTS and
Ubuntu 18.04 LTS. (CVE-2019-15605)
Alyssa Wilk discovered that Node.js incorrectly handled certain inputs. If a
user or an automated system were tricked in
GHSA
GHSA-3qv8-368w-r69p: Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons
ghsa_unreviewed·2022-05-24
CVE-2019-15606 [HIGH] CWE-20 GHSA-3qv8-368w-r69p: Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons
Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons
OSV
CVE-2019-15606: Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons
osv·2020-02-07·CVSS 9.8
CVE-2019-15606 [CRITICAL] CVE-2019-15606: Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons
Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00008.htmlhttps://access.redhat.com/errata/RHSA-2020:0573https://access.redhat.com/errata/RHSA-2020:0579https://access.redhat.com/errata/RHSA-2020:0597https://access.redhat.com/errata/RHSA-2020:0598https://access.redhat.com/errata/RHSA-2020:0602https://hackerone.com/reports/730779https://nodejs.org/en/blog/release/v10.19.0/https://nodejs.org/en/blog/release/v12.15.0/https://nodejs.org/en/blog/release/v13.8.0/https://nodejs.org/en/blog/vulnerability/february-2020-security-releases/https://security.gentoo.org/glsa/202003-48https://security.netapp.com/advisory/ntap-20200221-0004/https://www.debian.org/security/2020/dsa-4669https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-03/msg00008.htmlhttps://access.redhat.com/errata/RHSA-2020:0573https://access.redhat.com/errata/RHSA-2020:0579https://access.redhat.com/errata/RHSA-2020:0597https://access.redhat.com/errata/RHSA-2020:0598https://access.redhat.com/errata/RHSA-2020:0602https://hackerone.com/reports/730779https://nodejs.org/en/blog/release/v10.19.0/https://nodejs.org/en/blog/release/v12.15.0/https://nodejs.org/en/blog/release/v13.8.0/https://nodejs.org/en/blog/vulnerability/february-2020-security-releases/https://security.gentoo.org/glsa/202003-48https://security.netapp.com/advisory/ntap-20200221-0004/https://www.debian.org/security/2020/dsa-4669https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2020.html
2020-02-07
Published