Node.js < 12.18.4 and < 14.11 can be exploited to...
Vulnerability Description
Node.js < 12.18.4 and < 14.11 can be exploited to perform HTTP desync attacks and deliver malicious payloads to unsuspecting users. The payloads can be crafted by an attacker to hijack user sessions, poison cookies, perform clickjacking, and a multitude of other attacks depending on the architecture of the underlying system. The attack was possible due to a bug in processing of carrier-return symbols in the HTTP header names.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-8201
Credits & Attribution
No credits recorded in the NVD database.
References
- https://nodejs.org/en/blog/vulnerability/september-2020-security-releases/
- https://hackerone.com/reports/922597
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00011.html
- https://security.netapp.com/advisory/ntap-20201009-0004/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4OOYAMJVLLCLXDTHW3V5UXNULZBBK4O6/
- https://security.gentoo.org/glsa/202101-07
More from NodeJS
View All →Affected Vendor
NodeJS
View all reports →