Resource exhaustion in Node.js - CVE-2018-12122
Published: November 29, 2018
Vulnerability details
The vulnerability exists due to the socket is destroyed on the next received chunk when headers are not completely received within this period. A remote attacker can send headers very slowly keeping HTTP or HTTPS connections and associated resources alive for a long period of time, consume excessive resources and cause the service to crash.
Affected software
Gentoo Linux
Opensuse
IBM Cloud Transformation Advisor
nodejs-current (Alpine package)
rh-nodejs8-nodejs (Red Hat package)
How to mitigate CVE-2018-12122
IBM Cloud Transformation Advisor - update to 1.9.2
nodejs-current (Alpine package) - update to 11.3.0-r0
rh-nodejs8-nodejs (Red Hat package) - update to 8.16.0-1.el7
External References
Related Security Bulletins
- Multiple vulnerabilities in Node.js
- OpenSUSE Linux update for nodejs4
- OpenSUSE Linux update for nodejs8
- OpenSUSE Linux update for nodejs6
- Gentoo update for Node.js
- Resource exhaustion in nodejs-current (Alpine package)
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Red Hat Software Collections update for rh-nodejs8-nodejs