CVE-2020-8201
Last modified
CVE-2020-8201 is a high-severity vulnerability rated 7.4/10 on the CVSS scale. Node.js < 12.18.4 and < 14.11 can be exploited to perform HTTP desync attacks and deliver malicious payloads to unsuspecting users. The payloads can be crafted by an attacker to hijack user sessions, poison cookies, perform clickjacking, and a multitude of other attacks depending on the architecture of the underlying system. EPSS estimates a 5.09% chance of exploitation in the next 30 days.
Description
Node.js < 12.18.4 and < 14.11 can be exploited to perform HTTP desync attacks and deliver malicious payloads to unsuspecting users. The payloads can be crafted by an attacker to hijack user sessions, poison cookies, perform clickjacking, and a multitude of other attacks depending on the architecture of the underlying system. The attack was possible due to a bug in processing of carrier-return symbols in the HTTP header names.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nodejs | Node.Js | >= 12.0.0, < 12.18.4 |
| Nodejs | Node.Js | >= 14.0.0, < 14.11.0 |
| Opensuse | Leap | 15.2 |
| Fedoraproject | Fedora | 33 |
References
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00011.htmlThird Party Advisory
- https://hackerone.com/reports/922597Permissions Required
- https://security.gentoo.org/glsa/202101-07Third Party Advisory
- https://security.netapp.com/advisory/ntap-20201009-0004/Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00011.htmlThird Party Advisory
- https://hackerone.com/reports/922597Permissions Required
- https://security.gentoo.org/glsa/202101-07Third Party Advisory
- https://security.netapp.com/advisory/ntap-20201009-0004/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-8201?
How severe is CVE-2020-8201?
How do I fix CVE-2020-8201?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-8195Improper input validation in Citrix ADC and Citrix Gateway v…6.5
- CVE-2020-8196Improper access control in Citrix ADC and Citrix Gateway ver…4.3
- CVE-2020-8197Privilege escalation vulnerability on Citrix ADC and Citrix …8.8
- CVE-2020-8198Improper input validation in Citrix ADC and Citrix Gateway v…6.1
- CVE-2020-8199Improper access control in Citrix ADC Gateway Linux client v…7.8
- CVE-2020-8200Improper authentication in Citrix StoreFront Server < 1912.0…6.5
- CVE-2020-8202Improper check of inputs in Nextcloud Preferred Providers ap…5.3
- CVE-2020-8203Prototype pollution attack when using _.zipObjectDeep in lod…7.4
- CVE-2020-8204A cross site scripting (XSS) vulnerability exists in Pulse C…6.1
- CVE-2020-8205The uppy npm package < 1.13.2 and < 2.0.0-alpha.5 is vulnera…7.5
- CVE-2020-8206An improper authentication vulnerability exists in Pulse Con…8.1
- CVE-2020-8207Improper access control in Citrix Workspace app for Windows …8.8
Are you affected by CVE-2020-8201?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
