Lucene search

K
cvelistHackeroneCVELIST:CVE-2019-15606
HistoryFeb 07, 2020 - 2:58 p.m.

CVE-2019-15606

2020-02-0714:58:08
CWE-20
hackerone
www.cve.org

9.6 High

AI Score

Confidence

High

0.014 Low

EPSS

Percentile

86.6%

Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons

CNA Affected

[
  {
    "product": "https://github.com/nodejs/node",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "10.19.0, 12.15.0, 13.8.0"
      }
    ]
  }
]