Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2020-8287 #1

Open
ISCAS-Vulab opened this issue May 21, 2024 · 0 comments
Open

CVE-2020-8287 #1

ISCAS-Vulab opened this issue May 21, 2024 · 0 comments

Comments

@ISCAS-Vulab
Copy link

ISCAS-Vulab commented May 21, 2024

We have found that a vulnerabilitiy contained in your software have been updated,details:
CVE: CVE-2020-8287
Description: Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 allow two copies of a header field in an HTTP request (for example, two Transfer-Encoding header fields). In this case, Node.js identifies the first header field and ignores the second. This can lead to HTTP Request Smuggling.
Affected software: ['debian linux', 'sinec infrastructure network services', 'fedora', 'graalvm', 'node.js']
Threat score: 6.5
Patch recommand: https://nodejs.org/en/blog/vulnerability/january-2021-security-releases/
Poc recommand: https://hackerone.com/reports/1002188
Reference: https://nvd.nist.gov/vuln/detail/CVE-2020-8287
If you have any questions, you can contact:[email protected]

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant