Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-15605

Опубликовано: 07 фев. 2020
Источник: redhat
CVSS3: 7.1

Описание

HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed

A flaw was found in the Node.js code where a specially crafted HTTP(s) request sent to a Node.js server failed to properly process the HTTP(s) headers, resulting in a request smuggling attack. An attacker can use this flaw to alter a request sent as an authenticated user if the Node.js server is deployed behind a proxy server that reuses connections.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Quay 3quayNot affected
Red Hat Enterprise Linux 7http-parserFixedRHSA-2020:070304.03.2020
Red Hat Enterprise Linux 7.6 Extended Update Supporthttp-parserFixedRHSA-2020:151021.04.2020
Red Hat Enterprise Linux 8nodejsFixedRHSA-2020:057925.02.2020
Red Hat Enterprise Linux 8nodejsFixedRHSA-2020:059825.02.2020
Red Hat Enterprise Linux 8http-parserFixedRHSA-2020:070804.03.2020
Red Hat Enterprise Linux 8.0 Update Services for SAP SolutionsnodejsFixedRHSA-2020:057324.02.2020
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutionshttp-parserFixedRHSA-2020:070704.03.2020
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-nodejs10-nodejsFixedRHSA-2020:059725.02.2020
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-nodejs12-nodejsFixedRHSA-2020:060225.02.2020

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-444
https://bugzilla.redhat.com/show_bug.cgi?id=1800364nodejs: HTTP request smuggling using malformed Transfer-Encoding header

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 5 лет назад

HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed

CVSS3: 9.8
nvd
больше 5 лет назад

HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed

CVSS3: 9.8
debian
больше 5 лет назад

HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payl ...

CVSS3: 9.8
github
около 3 лет назад

HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed

oracle-oval
больше 5 лет назад

ELSA-2020-0708: http-parser security update (IMPORTANT)

7.1 High

CVSS3