Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published: 2020-02-07T14:58:08

Updated: 2024-08-05T00:49:13.841Z

Reserved: 2019-08-26T00:00:00

Link: CVE-2019-15606

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-02-07T15:15:11.413

Modified: 2024-03-07T21:24:40.750

Link: CVE-2019-15606

cve-icon Redhat

Severity : Moderate

Publid Date: 2020-02-07T00:00:00Z

Links: CVE-2019-15606 - Bugzilla