HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed
References
Link Resource
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00008.html Mailing List Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0573 Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0579 Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0597 Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0598 Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0602 Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0703 Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0707 Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0708 Third Party Advisory
https://hackerone.com/reports/735748 Permissions Required Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CT3WTR4P5VAJ3GJGKPYEDUPTNZ3IEDUR/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZLB676PDU4RJQLWQUA277YNGYYNEYGWO/
https://nodejs.org/en/blog/release/v10.19.0/ Release Notes Vendor Advisory
https://nodejs.org/en/blog/release/v12.15.0/ Release Notes Vendor Advisory
https://nodejs.org/en/blog/release/v13.8.0/ Vendor Advisory
https://nodejs.org/en/blog/vulnerability/february-2020-security-releases/ Vendor Advisory
https://security.gentoo.org/glsa/202003-48 Third Party Advisory
https://security.netapp.com/advisory/ntap-20200221-0004/ Third Party Advisory
https://www.debian.org/security/2020/dsa-4669 Third Party Advisory
https://www.oracle.com//security-alerts/cpujul2021.html Patch Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2020.html Patch Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: hackerone

Published: 2020-02-07T14:55:22

Updated: 2021-07-20T22:53:35

Reserved: 2019-08-26T00:00:00


Link: CVE-2019-15605

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2020-02-07T15:15:11.287

Modified: 2024-03-07T21:24:40.750


Link: CVE-2019-15605

JSON object: View

cve-icon Redhat Information

No data.

CWE