CVE-2020-8201
Summary
| CVE | CVE-2020-8201 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-09-18 21:15:00 UTC |
| Updated | 2023-11-07 03:26:00 UTC |
| Description | Node.js < 12.18.4 and < 14.11 can be exploited to perform HTTP desync attacks and deliver malicious payloads to unsuspecting users. The payloads can be crafted by an attacker to hijack user sessions, poison cookies, perform clickjacking, and a multitude of other attacks depending on the architecture of the underlying system. The attack was possible due to a bug in processing of carrier-return symbols in the HTTP header names. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| October 2020 Node.js Vulnerabilities in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| September 2020 Security Releases | Node.js |
MISC |
nodejs.org |
Vendor Advisory |
| [SECURITY] Fedora 33 Update: nodejs-14.15.1-1.fc33 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| NodeJS: Multiple vulnerabilities (GLSA 202101-07) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| [SECURITY] Fedora 33 Update: nodejs-14.15.1-1.fc33 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| HackerOne |
MISC |
hackerone.com |
Permissions Required |
| [security-announce] openSUSE-SU-2020:1616-1: important: Security update |
SUSE |
lists.opensuse.org |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 376248 IBM Spectrum Control Multiple Vulnerabilities (6359903,6359899,6359901)
- 500437 Alpine Linux Security Update for nodejs
- 501636 Alpine Linux Security Update for nodejs-current
- 504200 Alpine Linux Security Update for nodejs
- 690520 Free Berkeley Software Distribution (FreeBSD) Security Update for node.js (4ca5894c-f7f1-11ea-8ff8-0022489ad614)
- 940128 AlmaLinux Security Update for nodejs:12 (ALSA-2020:4272)