ZeroHour

CVE-2020-8287

PoC
CVSS 3.1
6.5 medium
EPSS
16%p97
Published
()
Modified
Description

Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 allow two copies of a header field in an HTTP request (for example, two Transfer-Encoding header fields). In this case, Node.js identifies the first header field and ignores the second. This can lead to HTTP Request Smuggling.

Vendors
nodejsdebianfedoraprojectoraclesiemens
Products
node.js, debian linux, fedora, graalvm, sinec infrastructure network services
Weakness
CWE-444
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.