Node.js — программная платформа, основанная на движке V8 (компилирующем JavaScript в машинный код)
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 24.21.0 | 24.21.0 | ||
| 24.20.0 | 24.20.0 | ||
| 24.19.0 | 24.19.0 | ||
| 24.18.1 | 24.18.1 | ||
| 24.18.0 | 24.18.0 | ||
| 24.17.0 | 24.17.0 | ||
| 24.16.0 | 24.16.0 | ||
| 24.15.0 | 24.15.0 | ||
| 24.14.1 | 24.14.1 | ||
| 24.14.0 | 24.14.0 |
Показывать по
Количество 1 270
openSUSE-SU-2019:1432-1
Security update for openssl-1_0_0
openSUSE-SU-2019:1211-1
Security update for nodejs10
BDU:2019-03647
Уязвимость сетевого протокола HTTP/2 веб-сервера Apache Traffic Server, программной платформы Node.js, связанная с недостатком механизма контроля расхода ресурсов, позволяющая нарушителю вызвать отказ в обслуживании
openSUSE-SU-2019:1175-1
Security update for openssl
openSUSE-SU-2019:1105-1
Security update for openssl-1_0_0
SUSE-SU-2019:0803-1
Security update for openssl
CVE-2019-5739
Keep-alive HTTP and HTTPS connections can remain open and inactive for ...
CVE-2019-5739
Keep-alive HTTP and HTTPS connections can remain open and inactive for up to 2 minutes in Node.js 6.16.0 and earlier. Node.js 8.0.0 introduced a dedicated server.keepAliveTimeout which defaults to 5 seconds. The behavior in Node.js 6.16.0 and earlier is a potential Denial of Service (DoS) attack vector. Node.js 6.17.0 introduces server.keepAliveTimeout and the 5-second default.
CVE-2019-5737
In Node.js including 6.x before 6.17.0, 8.x before 8.15.1, 10.x before ...
CVE-2019-5737
In Node.js including 6.x before 6.17.0, 8.x before 8.15.1, 10.x before 10.15.2, and 11.x before 11.10.1, an attacker can cause a Denial of Service (DoS) by establishing an HTTP or HTTPS connection in keep-alive mode and by sending headers very slowly. This keeps the connection and associated resources alive for a long period of time. Potential attacks are mitigated by the use of a load balancer or other proxy layer. This vulnerability is an extension of CVE-2018-12121, addressed in November and impacts all active Node.js release lines including 6.x before 6.17.0, 8.x before 8.15.1, 10.x before 10.15.2, and 11.x before 11.10.1.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
openSUSE-SU-2019:1432-1 Security update for openssl-1_0_0 | 17% Средний | больше 7 лет назад | ||
openSUSE-SU-2019:1211-1 Security update for nodejs10 | 16% Средний | больше 7 лет назад | ||
BDU:2019-03647 Уязвимость сетевого протокола HTTP/2 веб-сервера Apache Traffic Server, программной платформы Node.js, связанная с недостатком механизма контроля расхода ресурсов, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 7.5 | 28% Средний | больше 7 лет назад | |
openSUSE-SU-2019:1175-1 Security update for openssl | 17% Средний | больше 7 лет назад | ||
openSUSE-SU-2019:1105-1 Security update for openssl-1_0_0 | 17% Средний | больше 7 лет назад | ||
SUSE-SU-2019:0803-1 Security update for openssl | 17% Средний | больше 7 лет назад | ||
CVE-2019-5739 Keep-alive HTTP and HTTPS connections can remain open and inactive for ... | CVSS3: 7.5 | 5% Низкий | больше 7 лет назад | |
CVE-2019-5739 Keep-alive HTTP and HTTPS connections can remain open and inactive for up to 2 minutes in Node.js 6.16.0 and earlier. Node.js 8.0.0 introduced a dedicated server.keepAliveTimeout which defaults to 5 seconds. The behavior in Node.js 6.16.0 and earlier is a potential Denial of Service (DoS) attack vector. Node.js 6.17.0 introduces server.keepAliveTimeout and the 5-second default. | CVSS3: 7.5 | 5% Низкий | больше 7 лет назад | |
CVE-2019-5737 In Node.js including 6.x before 6.17.0, 8.x before 8.15.1, 10.x before ... | CVSS3: 7.5 | 16% Средний | больше 7 лет назад | |
CVE-2019-5737 In Node.js including 6.x before 6.17.0, 8.x before 8.15.1, 10.x before 10.15.2, and 11.x before 11.10.1, an attacker can cause a Denial of Service (DoS) by establishing an HTTP or HTTPS connection in keep-alive mode and by sending headers very slowly. This keeps the connection and associated resources alive for a long period of time. Potential attacks are mitigated by the use of a load balancer or other proxy layer. This vulnerability is an extension of CVE-2018-12121, addressed in November and impacts all active Node.js release lines including 6.x before 6.17.0, 8.x before 8.15.1, 10.x before 10.15.2, and 11.x before 11.10.1. | CVSS3: 7.5 | 16% Средний | больше 7 лет назад |
Уязвимостей на страницу