Resource exhaustion in Node.js - CVE-2020-11080

 

Resource exhaustion in Node.js - CVE-2020-11080

Published: June 3, 2020


Vulnerability identifier: #VU28538
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-11080
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources when processing HTTP/2 SETTINGS frames. A remote attacker can trigger high CPU load by sending large HTTP/2 SETTINGS frames and perform a denial of service (DoS) attack.


Affected software

Node.js
Amazon Linux AMI
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE CaaS Platform
SUSE MicroOS
SUSE Enterprise Storage
SUSE OpenStack Cloud
Fedora
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
SUSE OpenStack Cloud Crowbar
HPE Helion Openstack
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
Opensuse
Ubuntu
nghttp2
e-mesh EMS
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-nghttp2 (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
nodejs (Alpine package)
jbcs-httpd24-curl (Red Hat package)
nodejs (Debian package)
rh-nodejs10-nodejs (Red Hat package)
nodejs-current (Alpine package)
libnghttp2-14 (Ubuntu package)
nghttp2-server (Ubuntu package)
nghttp2-client (Ubuntu package)
libnghttp2-dev (Ubuntu package)
nghttp2 (Ubuntu package)
nghttp2-proxy (Ubuntu package)
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
servicemesh-proxy (Red Hat package)
httpd24-nghttp2 (Red Hat package)
nghttp2 (Red Hat package)
nghttp2
nghttp2-debugsource
libnghttp2-14
libnghttp2-14-32bit
libnghttp2-14-debuginfo
libnghttp2-14-debuginfo-32bit
nghttp2-debuginfo
libnghttp2-14-32bit-debuginfo
libnghttp2_asio1-debuginfo
libnghttp2_asio1
libnghttp2_asio-devel
libnghttp2-devel
jbcs-httpd24-mod_md (Red Hat package)
rh-nodejs12-nodejs (Red Hat package)
nodejs
IBM Cloud Transformation Advisor
IBM Cloud Pak for Business Automation
Isolation Segment
VMware Tanzu Application Service for VMs
Dell EMC PowerProtect Data Protection
Oracle Enterprise Communications Broker
SmartFabric OS10
Enterprise SONiC
Platform Automation Toolkit
Dell PowerProtect Cyber Recovery
Quay
Oracle GraalVM Enterprise Edition
Oracle Communications Session Border Controller
Red Hat OpenShift Container Platform
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
IBM CICS TX Advanced

How to mitigate CVE-2020-11080

Install updates from vendor's website.

Node.js - addressed in versions 10.21.0, 12.18.0, 14.4.0
nghttp2 - update to 1.41.0
e-mesh EMS - update to 1.0.1
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.7-3.jbcs.el6, 1.15.7-3.jbcs.el7
jbcs-httpd24-nghttp2 (Red Hat package) - addressed in versions 1.39.2-25.jbcs.el6, 1.39.2-25.jbcs.el7
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.37-57.jbcs.el6, 2.4.37-57.jbcs.el7
Dell EMC PowerProtect Data Protection - update to 2.7.8
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.2-51.GA.jbcs.el6, 2.9.2-51.GA.jbcs.el7
Quay - update to 3.3.1
nodejs (Alpine package) - update to 12.18.3-r0
jbcs-httpd24-curl (Red Hat package) - addressed in versions 7.64.1-36.jbcs.el6, 7.64.1-36.jbcs.el7
nodejs (Debian package) - update to 10.21.0~dfsg-1~deb10u1
SmartFabric OS10 - addressed in versions 10.5.4.11, 10.5.6.1
rh-nodejs10-nodejs (Red Hat package) - update to 10.21.0-3.el7
nodejs-current (Alpine package) - update to 14.4.0-r0
IBM Cloud Pak for Business Automation - update to 20.0.2 ifix 001
libnghttp2-14 (Ubuntu package) - addressed in versions Ubuntu Pro, 1.40.0-1ubuntu0.1
nghttp2-server (Ubuntu package) - addressed in versions Ubuntu Pro, 1.40.0-1ubuntu0.1
nghttp2-client (Ubuntu package) - addressed in versions Ubuntu Pro, 1.40.0-1ubuntu0.1
libnghttp2-dev (Ubuntu package) - addressed in versions Ubuntu Pro, 1.40.0-1ubuntu0.1
nghttp2 (Ubuntu package) - addressed in versions Ubuntu Pro, 1.40.0-1ubuntu0.1
nghttp2-proxy (Ubuntu package) - addressed in versions Ubuntu Pro, 1.40.0-1ubuntu0.1
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - update to 0.4.10-7.jbcs.el7
servicemesh-proxy (Red Hat package) - addressed in versions 1.0.10-3.el8, 1.1.2-3.el8
httpd24-nghttp2 (Red Hat package) - addressed in versions 1.7.1-8.el6.1, 1.7.1-8.el7.1
nghttp2 (Red Hat package) - addressed in versions 1.33.0-1.el8_0.2, 1.33.0-3.el8_1.1, 1.33.0-3.el8_2.1
nghttp2 - addressed in versions 1.33.0-1.1.el7, 1.41.0-1.fc31
nghttp2-debugsource - addressed in versions 1.39.2-3.5.1, 1.40.0-3.5.1, 1.40.0-3.11.1
libnghttp2-14 - addressed in versions 1.39.2-3.5.1, 1.40.0-3.5.1, 1.40.0-3.11.1
libnghttp2-14-32bit - addressed in versions 1.39.2-3.5.1, 1.40.0-3.5.1, 1.40.0-3.11.1
libnghttp2-14-debuginfo - addressed in versions 1.39.2-3.5.1, 1.40.0-3.5.1, 1.40.0-3.11.1
libnghttp2-14-debuginfo-32bit - update to 1.39.2-3.5.1
nghttp2-debuginfo - addressed in versions 1.39.2-3.5.1, 1.40.0-3.5.1, 1.40.0-3.11.1
libnghttp2-14-32bit-debuginfo - addressed in versions 1.40.0-3.5.1, 1.40.0-3.11.1
libnghttp2_asio1-debuginfo - addressed in versions 1.40.0-3.5.1, 1.40.0-3.11.1
libnghttp2_asio1 - addressed in versions 1.40.0-3.5.1, 1.40.0-3.11.1
libnghttp2_asio-devel - addressed in versions 1.40.0-3.5.1, 1.40.0-3.11.1
libnghttp2-devel - addressed in versions 1.40.0-3.5.1, 1.40.0-3.11.1
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.0.8-24.jbcs.el6, 2.0.8-24.jbcs.el7
Isolation Segment - addressed in versions 2.11.36, 2.13.21, 3.0.14, 4.0.5
VMware Tanzu Application Service for VMs - addressed in versions 2.11.42, 2.13.24, 3.0.14, 4.0.5
Enterprise SONiC - update to 4.2.1
Platform Automation Toolkit - addressed in versions 4.4.32, 5.0.25, 5.1.2
Red Hat OpenShift Container Platform - update to 4.5.8
Dell EMC Unity Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity XT Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity VSA Operating Environment (OE) - update to 5.1.2.0.5.007
IBM CICS TX Advanced - update to 10.1.0.0 ifix21
rh-nodejs12-nodejs (Red Hat package) - update to 12.18.2-1.el7
nodejs - addressed in versions 14.15.1-1.fc33, 14-3220201203015508.43bbeeef, 14-3320201203015508.601d93de
Dell PowerProtect Cyber Recovery - update to 19.14.0.1

External References

Related Security Bulletins