CVE-2019-5737

node.js: Uncontrolled Resource Consumption (CVE-2019-5737)

Description

In Node.js including 6.x before 6.17.0, 8.x before 8.15.1, 10.x before 10.15.2, and 11.x before 11.10.1, an attacker can cause a Denial of Service (DoS) by establishing an HTTP or HTTPS connection in keep-alive mode and by sending headers very slowly. This keeps the connection and associated resources alive for a long period of time. Potential attacks are mitigated by the use of a load balancer or other proxy layer. This vulnerability is an extension of CVE-2018-12121, addressed in November and impacts all active Node.js release lines including 6.x before 6.17.0, 8.x before 8.15.1, 10.x before 10.15.2, and 11.x before 11.10.1.

Source: CVELISTV5NVD

Metrics

Severity
high
no public PoC known
7.5
Source: nvd-v3
96.7 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
16.2 %
Elevated — model estimates 10-50% exploitation likelihood.
Published
2019-03-28 16:20 UTC
CWE-400

Weakness classes (CWE)

  • CWE-400Class

    Uncontrolled Resource Consumption

    The product does not properly control the allocation and maintenance of a limited resource.

    cwe.mitre.org →

Affected operating systems

  • linux

    opensuse / leap42.3

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • nodejs

    node.js10.0.0 – 10.15.2

  • nodejs

    node.js11.0.0 – 11.10.1

  • nodejs

    node.js6.0.0 – 6.17.0

  • nodejs

    node.js8.0.0 – 8.15.1

References & sources

IDCVE-2019-5737