Resource exhaustion in Node.js - CVE-2020-11080
Published: June 3, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when processing HTTP/2 SETTINGS frames. A remote attacker can trigger high CPU load by sending large HTTP/2 SETTINGS frames and perform a denial of service (DoS) attack.
Affected software
Amazon Linux AMI
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE CaaS Platform
SUSE MicroOS
SUSE Enterprise Storage
SUSE OpenStack Cloud
Fedora
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
SUSE OpenStack Cloud Crowbar
HPE Helion Openstack
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
Opensuse
Ubuntu
nghttp2
e-mesh EMS
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-nghttp2 (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
nodejs (Alpine package)
jbcs-httpd24-curl (Red Hat package)
nodejs (Debian package)
rh-nodejs10-nodejs (Red Hat package)
nodejs-current (Alpine package)
libnghttp2-14 (Ubuntu package)
nghttp2-server (Ubuntu package)
nghttp2-client (Ubuntu package)
libnghttp2-dev (Ubuntu package)
nghttp2 (Ubuntu package)
nghttp2-proxy (Ubuntu package)
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
servicemesh-proxy (Red Hat package)
httpd24-nghttp2 (Red Hat package)
nghttp2 (Red Hat package)
nghttp2
nghttp2-debugsource
libnghttp2-14
libnghttp2-14-32bit
libnghttp2-14-debuginfo
libnghttp2-14-debuginfo-32bit
nghttp2-debuginfo
libnghttp2-14-32bit-debuginfo
libnghttp2_asio1-debuginfo
libnghttp2_asio1
libnghttp2_asio-devel
libnghttp2-devel
jbcs-httpd24-mod_md (Red Hat package)
rh-nodejs12-nodejs (Red Hat package)
nodejs
IBM Cloud Transformation Advisor
IBM Cloud Pak for Business Automation
Isolation Segment
VMware Tanzu Application Service for VMs
Dell EMC PowerProtect Data Protection
Oracle Enterprise Communications Broker
SmartFabric OS10
Enterprise SONiC
Platform Automation Toolkit
Dell PowerProtect Cyber Recovery
Quay
Oracle GraalVM Enterprise Edition
Oracle Communications Session Border Controller
Red Hat OpenShift Container Platform
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
IBM CICS TX Advanced
How to mitigate CVE-2020-11080
nghttp2 - update to 1.41.0
e-mesh EMS - update to 1.0.1
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.7-3.jbcs.el6, 1.15.7-3.jbcs.el7
jbcs-httpd24-nghttp2 (Red Hat package) - addressed in versions 1.39.2-25.jbcs.el6, 1.39.2-25.jbcs.el7
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.37-57.jbcs.el6, 2.4.37-57.jbcs.el7
Dell EMC PowerProtect Data Protection - update to 2.7.8
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.2-51.GA.jbcs.el6, 2.9.2-51.GA.jbcs.el7
Quay - update to 3.3.1
nodejs (Alpine package) - update to 12.18.3-r0
jbcs-httpd24-curl (Red Hat package) - addressed in versions 7.64.1-36.jbcs.el6, 7.64.1-36.jbcs.el7
nodejs (Debian package) - update to 10.21.0~dfsg-1~deb10u1
SmartFabric OS10 - addressed in versions 10.5.4.11, 10.5.6.1
rh-nodejs10-nodejs (Red Hat package) - update to 10.21.0-3.el7
nodejs-current (Alpine package) - update to 14.4.0-r0
IBM Cloud Pak for Business Automation - update to 20.0.2 ifix 001
libnghttp2-14 (Ubuntu package) - addressed in versions Ubuntu Pro, 1.40.0-1ubuntu0.1
nghttp2-server (Ubuntu package) - addressed in versions Ubuntu Pro, 1.40.0-1ubuntu0.1
nghttp2-client (Ubuntu package) - addressed in versions Ubuntu Pro, 1.40.0-1ubuntu0.1
libnghttp2-dev (Ubuntu package) - addressed in versions Ubuntu Pro, 1.40.0-1ubuntu0.1
nghttp2 (Ubuntu package) - addressed in versions Ubuntu Pro, 1.40.0-1ubuntu0.1
nghttp2-proxy (Ubuntu package) - addressed in versions Ubuntu Pro, 1.40.0-1ubuntu0.1
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - update to 0.4.10-7.jbcs.el7
servicemesh-proxy (Red Hat package) - addressed in versions 1.0.10-3.el8, 1.1.2-3.el8
httpd24-nghttp2 (Red Hat package) - addressed in versions 1.7.1-8.el6.1, 1.7.1-8.el7.1
nghttp2 (Red Hat package) - addressed in versions 1.33.0-1.el8_0.2, 1.33.0-3.el8_1.1, 1.33.0-3.el8_2.1
nghttp2 - addressed in versions 1.33.0-1.1.el7, 1.41.0-1.fc31
nghttp2-debugsource - addressed in versions 1.39.2-3.5.1, 1.40.0-3.5.1, 1.40.0-3.11.1
libnghttp2-14 - addressed in versions 1.39.2-3.5.1, 1.40.0-3.5.1, 1.40.0-3.11.1
libnghttp2-14-32bit - addressed in versions 1.39.2-3.5.1, 1.40.0-3.5.1, 1.40.0-3.11.1
libnghttp2-14-debuginfo - addressed in versions 1.39.2-3.5.1, 1.40.0-3.5.1, 1.40.0-3.11.1
libnghttp2-14-debuginfo-32bit - update to 1.39.2-3.5.1
nghttp2-debuginfo - addressed in versions 1.39.2-3.5.1, 1.40.0-3.5.1, 1.40.0-3.11.1
libnghttp2-14-32bit-debuginfo - addressed in versions 1.40.0-3.5.1, 1.40.0-3.11.1
libnghttp2_asio1-debuginfo - addressed in versions 1.40.0-3.5.1, 1.40.0-3.11.1
libnghttp2_asio1 - addressed in versions 1.40.0-3.5.1, 1.40.0-3.11.1
libnghttp2_asio-devel - addressed in versions 1.40.0-3.5.1, 1.40.0-3.11.1
libnghttp2-devel - addressed in versions 1.40.0-3.5.1, 1.40.0-3.11.1
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.0.8-24.jbcs.el6, 2.0.8-24.jbcs.el7
Isolation Segment - addressed in versions 2.11.36, 2.13.21, 3.0.14, 4.0.5
VMware Tanzu Application Service for VMs - addressed in versions 2.11.42, 2.13.24, 3.0.14, 4.0.5
Enterprise SONiC - update to 4.2.1
Platform Automation Toolkit - addressed in versions 4.4.32, 5.0.25, 5.1.2
Red Hat OpenShift Container Platform - update to 4.5.8
Dell EMC Unity Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity XT Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity VSA Operating Environment (OE) - update to 5.1.2.0.5.007
IBM CICS TX Advanced - update to 10.1.0.0 ifix21
rh-nodejs12-nodejs (Red Hat package) - update to 12.18.2-1.el7
nodejs - addressed in versions 14.15.1-1.fc33, 14-3220201203015508.43bbeeef, 14-3320201203015508.601d93de
Dell PowerProtect Cyber Recovery - update to 19.14.0.1
External References
Related Security Bulletins
- Multiple vulnerabilities in Node.js
- Debian update for nodejs
- Denial of service in nghttp2
- Red Hat update for Red Hat JBoss Core Services Apache HTTP Server 2.4.37 SP3
- Multiple vulnerabilities in Oracle GraalVM Enterprise Edition
- Red Hat Software Collections update for rh-nodejs10-nodejs
- Amazon Linux AMI update for nghttp2
- OpenSUSE Linux update for nodejs8
- Multiple vulnerabilities in Red Hat Quay
- Resource exhaustion in nodejs (Alpine package)
- Resource exhaustion in nodejs-current (Alpine package)
- Multiple vulnerabilities in Oracle Communications Session Border Controller
- Multiple vulnerabilities in Oracle Enterprise Communications Broker
- Multiple vulnerabilities in Dell EMC Unity
- Multiple vulnerabilities in Hitachi Energy e-mesh EMS
- OpenShift Service Mesh 1.1 update for servicemesh-proxy
- OpenShift Service Mesh 1.0 update for servicemesh-proxy
- Red Hat Enterprise Linux 8 update for nghttp2
- Red Hat Software Collections update for httpd24-nghttp2
- Red Hat Enterprise Linux 8.1 Extended Update Support update for nghttp2
- Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions update for nghttp2
- Red Hat Software Collections update for rh-nodejs12-nodejs
- SUSE update for nghttp2
- SUSE update for nghttp2
- SUSE update for nghttp2
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Ubuntu update for nghttp2
- Multiple vulnerabilities in Dell PowerProtect Cyber Recovery
- Multiple vulnerabilities in IBM CICS TX Advanced
- VMware Tanzu products update for nghttp2
- Multiple vulnerabilities in Dell Networking OS10
- Multiple vulnerabilities in Dell Enterprise SONiC Distribution
- Multiple vulnerabilities in Dell SmartFabric OS10
- PowerProtect Data Protection software update for third-party components
- Red Hat Enterprise Linux 8 update for the nodejs:10 module
- Red Hat Enterprise Linux 8 update for the nodejs:10 module
- Red Hat Enterprise Linux 8 update for the nodejs:12 module
- Red Hat Enterprise Linux 8 update for the nodejs:12 module
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.5
- Fedora 31 update for nghttp2
- Fedora EPEL 7 update for nghttp2
- Fedora 32 Modular update for nodejs
- Fedora 33 Modular update for nodejs
- Fedora 33 update for nodejs
- Multiple vulnerabilities in IBM Cloud Pak for Automation