Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-7161

Опубликовано: 12 июн. 2018
Источник: redhat
CVSS3: 7.5

Описание

All versions of Node.js 8.x, 9.x, and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of service (DoS) by causing a node server providing an http2 server to crash. This can be accomplished by interacting with the http2 server in a manner that triggers a cleanup bug where objects are used in native code after they are no longer available. This has been addressed by updating the http2 implementation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8nodejsNot affected
Red Hat Mobile Application Platform 4nodejsNot affected
Red Hat OpenShift Application RuntimesnodejsNot affected
Red Hat OpenShift Container Platform 3.10logging-auth-proxyNot affected
Red Hat OpenShift Container Platform 3.10logging-kibanaNot affected
Red Hat Software Collectionsrh-nodejs4-nodejsNot affected
Red Hat Software Collectionsrh-nodejs6-nodejsNot affected
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-nodejs8-nodejsFixedRHSA-2018:294918.10.2018
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUSrh-nodejs8-nodejsFixedRHSA-2018:294918.10.2018
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSrh-nodejs8-nodejsFixedRHSA-2018:294918.10.2018

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1591013nodejs: denial of service (DoS) by causing a node server providing an http2 server to crash

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 7 лет назад

All versions of Node.js 8.x, 9.x, and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of service (DoS) by causing a node server providing an http2 server to crash. This can be accomplished by interacting with the http2 server in a manner that triggers a cleanup bug where objects are used in native code after they are no longer available. This has been addressed by updating the http2 implementation.

CVSS3: 7.5
nvd
около 7 лет назад

All versions of Node.js 8.x, 9.x, and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of service (DoS) by causing a node server providing an http2 server to crash. This can be accomplished by interacting with the http2 server in a manner that triggers a cleanup bug where objects are used in native code after they are no longer available. This has been addressed by updating the http2 implementation.

CVSS3: 7.5
msrc
около 4 лет назад

Описание отсутствует

CVSS3: 7.5
debian
около 7 лет назад

All versions of Node.js 8.x, 9.x, and 10.x are vulnerable and the seve ...

CVSS3: 7.5
github
около 3 лет назад

All versions of Node.js 8.x, 9.x, and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of service (DoS) by causing a node server providing an http2 server to crash. This can be accomplished by interacting with the http2 server in a manner that triggers a cleanup bug where objects are used in native code after they are no longer available. This has been addressed by updating the http2 implementation.

7.5 High

CVSS3