Resource exhaustion in Node.js - CVE-2020-8251

 

Resource exhaustion in Node.js - CVE-2020-8251

Published: September 18, 2020 / Updated: September 30, 2020


Vulnerability identifier: #VU47217
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-8251
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

Node.js < 14.11.0 is vulnerable to HTTP denial of service (DoS) attacks based on delayed requests submission which can make the server unable to accept new connections.


Affected software

Node.js
Gentoo Linux
Fedora
IBM Cloud Transformation Advisor
nodejs-current (Alpine package)
nodejs

How to mitigate CVE-2020-8251

Install update from vendor's website.

Node.js - update to 14.11.0
nodejs-current (Alpine package) - update to 14.11.0-r0
nodejs - addressed in versions 14.15.1-1.fc33, 14-3220201203015508.43bbeeef, 14-3320201203015508.601d93de

External References

Related Security Bulletins