ZeroHour

CVE-2019-15606

PoC
CVSS 3.1
9.8 critical
EPSS
20%p97
Published
()
Modified
Description

Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons

Vendors
nodejsoracledebianredhatopensuse
Products
node.js, communications cloud native core network function cloud native environment, graalvm, debian linux, enterprise linux, enterprise linux eus, leap
Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.