Логотип exploitDog
bind:CVE-2020-15168
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-15168

Количество 6

Количество 6

ubuntu логотип

CVE-2020-15168

больше 5 лет назад

node-fetch before versions 2.6.1 and 3.0.0-beta.9 did not honor the size option after following a redirect, which means that when a content size was over the limit, a FetchError would never get thrown and the process would end without failure. For most people, this fix will have a little or no impact. However, if you are relying on node-fetch to gate files above a size, the impact could be significant, for example: If you don't double-check the size of the data after fetch() has completed, your JS thread could get tied up doing work on a large file (DoS) and/or cost you money in computing.

CVSS3: 2.6
EPSS: Низкий
redhat логотип

CVE-2020-15168

больше 5 лет назад

node-fetch before versions 2.6.1 and 3.0.0-beta.9 did not honor the size option after following a redirect, which means that when a content size was over the limit, a FetchError would never get thrown and the process would end without failure. For most people, this fix will have a little or no impact. However, if you are relying on node-fetch to gate files above a size, the impact could be significant, for example: If you don't double-check the size of the data after fetch() has completed, your JS thread could get tied up doing work on a large file (DoS) and/or cost you money in computing.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2020-15168

больше 5 лет назад

node-fetch before versions 2.6.1 and 3.0.0-beta.9 did not honor the size option after following a redirect, which means that when a content size was over the limit, a FetchError would never get thrown and the process would end without failure. For most people, this fix will have a little or no impact. However, if you are relying on node-fetch to gate files above a size, the impact could be significant, for example: If you don't double-check the size of the data after fetch() has completed, your JS thread could get tied up doing work on a large file (DoS) and/or cost you money in computing.

CVSS3: 2.6
EPSS: Низкий
debian логотип

CVE-2020-15168

больше 5 лет назад

node-fetch before versions 2.6.1 and 3.0.0-beta.9 did not honor the si ...

CVSS3: 2.6
EPSS: Низкий
github логотип

GHSA-w7rc-rwvf-8q5r

больше 5 лет назад

The `size` option isn't honored after following a redirect in node-fetch

CVSS3: 2.6
EPSS: Низкий
fstec логотип

BDU:2021-02871

больше 4 лет назад

Уязвимость библиотеки node-fetch прикладного программного обеспечения Аврора Центр, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2020-15168

node-fetch before versions 2.6.1 and 3.0.0-beta.9 did not honor the size option after following a redirect, which means that when a content size was over the limit, a FetchError would never get thrown and the process would end without failure. For most people, this fix will have a little or no impact. However, if you are relying on node-fetch to gate files above a size, the impact could be significant, for example: If you don't double-check the size of the data after fetch() has completed, your JS thread could get tied up doing work on a large file (DoS) and/or cost you money in computing.

CVSS3: 2.6
0%
Низкий
больше 5 лет назад
redhat логотип
CVE-2020-15168

node-fetch before versions 2.6.1 and 3.0.0-beta.9 did not honor the size option after following a redirect, which means that when a content size was over the limit, a FetchError would never get thrown and the process would end without failure. For most people, this fix will have a little or no impact. However, if you are relying on node-fetch to gate files above a size, the impact could be significant, for example: If you don't double-check the size of the data after fetch() has completed, your JS thread could get tied up doing work on a large file (DoS) and/or cost you money in computing.

CVSS3: 5.3
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-15168

node-fetch before versions 2.6.1 and 3.0.0-beta.9 did not honor the size option after following a redirect, which means that when a content size was over the limit, a FetchError would never get thrown and the process would end without failure. For most people, this fix will have a little or no impact. However, if you are relying on node-fetch to gate files above a size, the impact could be significant, for example: If you don't double-check the size of the data after fetch() has completed, your JS thread could get tied up doing work on a large file (DoS) and/or cost you money in computing.

CVSS3: 2.6
0%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-15168

node-fetch before versions 2.6.1 and 3.0.0-beta.9 did not honor the si ...

CVSS3: 2.6
0%
Низкий
больше 5 лет назад
github логотип
GHSA-w7rc-rwvf-8q5r

The `size` option isn't honored after following a redirect in node-fetch

CVSS3: 2.6
0%
Низкий
больше 5 лет назад
fstec логотип
BDU:2021-02871

Уязвимость библиотеки node-fetch прикладного программного обеспечения Аврора Центр, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.3
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу