HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed
                
            References
                    Configurations
                    Configuration 1 (hide)
            
            
  | 
    
Configuration 2 (hide)
            
            
  | 
    
Configuration 3 (hide)
            
            
  | 
    
Configuration 4 (hide)
            
            
  | 
    
Configuration 5 (hide)
            
            
  | 
    
Configuration 6 (hide)
            
            
  | 
    
History
                    21 Nov 2024, 04:29
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00008.html - Mailing List, Third Party Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2020:0573 - Third Party Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2020:0579 - Third Party Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2020:0597 - Third Party Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2020:0598 - Third Party Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2020:0602 - Third Party Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2020:0703 - Third Party Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2020:0707 - Third Party Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2020:0708 - Third Party Advisory | |
| References | () https://hackerone.com/reports/735748 - Permissions Required, Third Party Advisory | |
| References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CT3WTR4P5VAJ3GJGKPYEDUPTNZ3IEDUR/ - | |
| References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZLB676PDU4RJQLWQUA277YNGYYNEYGWO/ - | |
| References | () https://nodejs.org/en/blog/release/v10.19.0/ - Release Notes, Vendor Advisory | |
| References | () https://nodejs.org/en/blog/release/v12.15.0/ - Release Notes, Vendor Advisory | |
| References | () https://nodejs.org/en/blog/release/v13.8.0/ - Vendor Advisory | |
| References | () https://nodejs.org/en/blog/vulnerability/february-2020-security-releases/ - Vendor Advisory | |
| References | () https://security.gentoo.org/glsa/202003-48 - Third Party Advisory | |
| References | () https://security.netapp.com/advisory/ntap-20200221-0004/ - Third Party Advisory | |
| References | () https://www.debian.org/security/2020/dsa-4669 - Third Party Advisory | |
| References | () https://www.oracle.com//security-alerts/cpujul2021.html - Patch, Third Party Advisory | |
| References | () https://www.oracle.com/security-alerts/cpuapr2020.html - Patch, Third Party Advisory | 
07 Mar 2024, 21:24
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* | 
07 Nov 2023, 03:05
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
        
        
  | 
    
        
        
  | 
Information
                Published : 2020-02-07 15:15
Updated : 2024-11-21 04:29
NVD link : CVE-2019-15605
Mitre link : CVE-2019-15605
CVE.ORG link : CVE-2019-15605
JSON object : View
Products Affected
                redhat
- enterprise_linux
 - enterprise_linux_eus
 - enterprise_linux_workstation
 - software_collections
 - enterprise_linux_desktop
 - enterprise_linux_server_aus
 - enterprise_linux_server_tus
 - enterprise_linux_server
 
oracle
- graalvm
 
nodejs
- node.js
 
debian
- debian_linux
 
fedoraproject
- fedora
 
opensuse
- leap
 
CWE
                
                    
                        
                        CWE-444
                        
            Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
