CVE-2019-5737
node.js: Uncontrolled Resource Consumption (CVE-2019-5737)
Description
In Node.js including 6.x before 6.17.0, 8.x before 8.15.1, 10.x before 10.15.2, and 11.x before 11.10.1, an attacker can cause a Denial of Service (DoS) by establishing an HTTP or HTTPS connection in keep-alive mode and by sending headers very slowly. This keeps the connection and associated resources alive for a long period of time. Potential attacks are mitigated by the use of a load balancer or other proxy layer. This vulnerability is an extension of CVE-2018-12121, addressed in November and impacts all active Node.js release lines including 6.x before 6.17.0, 8.x before 8.15.1, 10.x before 10.15.2, and 11.x before 11.10.1.
Metrics
Weakness classes (CWE)
CWE-400Class
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
cwe.mitre.org →
Affected operating systems
linux
opensuse / leap42.3
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
nodejs
node.js10.0.0 – 10.15.2
nodejs
node.js11.0.0 – 11.10.1
nodejs
node.js6.0.0 – 6.17.0
nodejs
node.js8.0.0 – 8.15.1
References & sources
- https://nodejs.org/en/blog/vulnerability/february-2019-security-releases/x_refsource_MISC
- http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00041.htmlvendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00046.htmlvendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00059.htmlvendor-advisoryx_refsource_SUSE
- https://security.netapp.com/advisory/ntap-20190502-0008/x_refsource_CONFIRM
- https://access.redhat.com/errata/RHSA-2019:1821vendor-advisoryx_refsource_REDHAT
- https://security.gentoo.org/glsa/202003-48vendor-advisoryx_refsource_GENTOO