CVE-2020-8201
Last modified
CVE-2020-8201 is a high-severity vulnerability rated 7.4/10 on the CVSS scale. Node.js < 12.18.4 and < 14.11 can be exploited to perform HTTP desync attacks and deliver malicious payloads to unsuspecting users. The payloads can be crafted by an attacker to hijack user sessions, poison cookies, perform clickjacking, and a multitude of other attacks depending on the architecture of the underlying system. EPSS estimates a 5.09% chance of exploitation in the next 30 days.
Description
Node.js < 12.18.4 and < 14.11 can be exploited to perform HTTP desync attacks and deliver malicious payloads to unsuspecting users. The payloads can be crafted by an attacker to hijack user sessions, poison cookies, perform clickjacking, and a multitude of other attacks depending on the architecture of the underlying system. The attack was possible due to a bug in processing of carrier-return symbols in the HTTP header names.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nodejs | Node.Js | >= 12.0.0, < 12.18.4 |
| Nodejs | Node.Js | >= 14.0.0, < 14.11.0 |
| Opensuse | Leap | 15.2 |
| Fedoraproject | Fedora | 33 |
References
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00011.htmlThird Party Advisory
- https://hackerone.com/reports/922597Permissions Required
- https://security.gentoo.org/glsa/202101-07Third Party Advisory
- https://security.netapp.com/advisory/ntap-20201009-0004/Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00011.htmlThird Party Advisory
- https://hackerone.com/reports/922597Permissions Required
- https://security.gentoo.org/glsa/202101-07Third Party Advisory
- https://security.netapp.com/advisory/ntap-20201009-0004/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-8201?
How severe is CVE-2020-8201?
How do I fix CVE-2020-8201?
Are you affected by CVE-2020-8201?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
