Resource exhaustion in Node.js - CVE-2020-8251
Published: September 18, 2020 / Updated: September 30, 2020
Vulnerability identifier: #VU47217
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-8251
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
Node.js < 14.11.0 is vulnerable to HTTP denial of service (DoS) attacks based on delayed requests submission which can make the server unable to accept new connections.
Affected software
Node.js
Gentoo Linux
Fedora
IBM Cloud Transformation Advisor
nodejs-current (Alpine package)
nodejs
Gentoo Linux
Fedora
IBM Cloud Transformation Advisor
nodejs-current (Alpine package)
nodejs
How to mitigate CVE-2020-8251
Install update from vendor's website.
Node.js - update to 14.11.0
nodejs-current (Alpine package) - update to 14.11.0-r0
nodejs - addressed in versions 14.15.1-1.fc33, 14-3220201203015508.43bbeeef, 14-3320201203015508.601d93de
nodejs-current (Alpine package) - update to 14.11.0-r0
nodejs - addressed in versions 14.15.1-1.fc33, 14-3220201203015508.43bbeeef, 14-3320201203015508.601d93de