Node.js — программная платформа, основанная на движке V8 (компилирующем JavaScript в машинный код)
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 24.21.0 | 24.21.0 | ||
| 24.20.0 | 24.20.0 | ||
| 24.19.0 | 24.19.0 | ||
| 24.18.1 | 24.18.1 | ||
| 24.18.0 | 24.18.0 | ||
| 24.17.0 | 24.17.0 | ||
| 24.16.0 | 24.16.0 | ||
| 24.15.0 | 24.15.0 | ||
| 24.14.1 | 24.14.1 | ||
| 24.14.0 | 24.14.0 |
Показывать по
Количество 1 270
BDU:2022-00330
Уязвимость программной платформы Node.js, связанная с непоследовательной интерпретацией http-запросов, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
BDU:2020-02545
Уязвимость программной платформы Node.js, связанная с недостаточной проверкой вводимых данных при обработке заголовков HTTP, позволяющая нарушителю получить полный контроль над приложением
ELSA-2019-3497
ELSA-2019-3497: http-parser security and bug fix update (MODERATE)
ELSA-2019-2893
ELSA-2019-2893: httpd:2.4 security update (IMPORTANT)
SUSE-SU-2019:14092-1
Security update for openssl
ELSA-2019-2471
ELSA-2019-2471: openssl security update (MODERATE)
CVE-2019-9518
Some HTTP/2 implementations are vulnerable to a flood of empty frames, ...
CVE-2019-9518
Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The attacker sends a stream of frames with an empty payload and without the end-of-stream flag. These frames can be DATA, HEADERS, CONTINUATION and/or PUSH_PROMISE. The peer spends time processing each frame disproportionate to attack bandwidth. This can consume excess CPU.
CVE-2019-9517
Some HTTP/2 implementations are vulnerable to unconstrained interal da ...
CVE-2019-9517
Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without constraint; however, they leave the TCP window closed so the peer cannot actually write (many of) the bytes on the wire. The attacker then sends a stream of requests for a large response object. Depending on how the servers queue the responses, this can consume excess memory, CPU, or both.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
BDU:2022-00330 Уязвимость программной платформы Node.js, связанная с непоследовательной интерпретацией http-запросов, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании | CVSS3: 9.8 | 57% Средний | больше 6 лет назад | |
BDU:2020-02545 Уязвимость программной платформы Node.js, связанная с недостаточной проверкой вводимых данных при обработке заголовков HTTP, позволяющая нарушителю получить полный контроль над приложением | CVSS3: 9.8 | 20% Средний | больше 6 лет назад | |
ELSA-2019-3497 ELSA-2019-3497: http-parser security and bug fix update (MODERATE) | 10% Средний | почти 7 лет назад | ||
ELSA-2019-2893 ELSA-2019-2893: httpd:2.4 security update (IMPORTANT) | 28% Средний | почти 7 лет назад | ||
SUSE-SU-2019:14092-1 Security update for openssl | 17% Средний | около 7 лет назад | ||
ELSA-2019-2471 ELSA-2019-2471: openssl security update (MODERATE) | 17% Средний | около 7 лет назад | ||
CVE-2019-9518 Some HTTP/2 implementations are vulnerable to a flood of empty frames, ... | CVSS3: 7.5 | 25% Средний | около 7 лет назад | |
CVE-2019-9518 Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The attacker sends a stream of frames with an empty payload and without the end-of-stream flag. These frames can be DATA, HEADERS, CONTINUATION and/or PUSH_PROMISE. The peer spends time processing each frame disproportionate to attack bandwidth. This can consume excess CPU. | CVSS3: 7.5 | 25% Средний | около 7 лет назад | |
CVE-2019-9517 Some HTTP/2 implementations are vulnerable to unconstrained interal da ... | CVSS3: 7.5 | 28% Средний | около 7 лет назад | |
CVE-2019-9517 Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without constraint; however, they leave the TCP window closed so the peer cannot actually write (many of) the bytes on the wire. The attacker then sends a stream of requests for a large response object. Depending on how the servers queue the responses, this can consume excess memory, CPU, or both. | CVSS3: 7.5 | 28% Средний | около 7 лет назад |
Уязвимостей на страницу