Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2019-15605 PoC — Joyent Node.js 环境问题漏洞

Source
Associated Vulnerability
Title:Joyent Node.js 环境问题漏洞 (CVE-2019-15605)
Description:Joyent Node.js是美国Joyent公司的一套建立在Google V8 JavaScript引擎之上的网络应用平台。该平台主要用于构建高度可伸缩的应用程序,以及编写能够处理数万条且同时连接到一个物理机的连接代码。 Joyent Node.js 10版本、12版本和13版本中存在环境问题漏洞。该漏洞源于网络系统或产品的环境因素不合理。
Description
PoC of Backend HTTP Socket Poisoning, via HTTP Smuggling, presented in CVE-2019-15605 
File Snapshot

[4.0K] /data/pocs/3b25334afbb13ac998b32b06e59aa04fe13ab2d9 ├── [4.0K] auth_strategies │   └── [ 292] session.js ├── [4.0K] client │   └── [ 0] fake_auth.js ├── [ 659] package.json ├── [ 54K] package-lock.json ├── [4.0K] poc │   └── [ 662] request.js ├── [4.0K] server │   └── [1.2K] app.js └── [ 608] smuggled_test.js 4 directories, 7 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.