Разработчики серверной JavaScript-платформы Node.js patches 13.8.0, 12.15.0 and 10.19.0, which fix three vulnerabilities:
- CVE-2019-15606 — improper handling of optional whitespace (OWS) that follows the value in the HTTP header;
- CVE-2019-15605 — the possibility of conducting an HRS (HTTP Request Smuggling, interfering with the contents of other requests processed in the same stream between the frontend and backend) through the submission of a specially crafted HTTP header Transfer-Encoding;
- CVE-2019-15604 — remotely initiated TLS server crash through the submission of an incorrect string in the certificate.
Additionally, the new releases have worked on enhancing the security of the HTTP parser and stricter parsing of HTTP request elements. This change may lead to compatibility issues with HTTP implementations that violate specification requirements. To disable strict mode checking, the insecureHTTPParser setting and the command line option "—insecure-http-parser" have been provided.
Burimi: opennet.ru
