CVE-2019-5739
node.js: Uncontrolled Resource Consumption (CVE-2019-5739)
highEPSS 5.1%
Description
Keep-alive HTTP and HTTPS connections can remain open and inactive for up to 2 minutes in Node.js 6.16.0 and earlier. Node.js 8.0.0 introduced a dedicated server.keepAliveTimeout which defaults to 5 seconds. The behavior in Node.js 6.16.0 and earlier is a potential Denial of Service (DoS) attack vector. Node.js 6.17.0 introduces server.keepAliveTimeout and the 5-second default.
Metrics
Severity
high
92.57
no public PoC known
7.5
91.8 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
Published
2019-03-28 16:27 UTC
CWE-400
Weakness classes (CWE)
CWE-400Class
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
cwe.mitre.org →
Affected operating systems
linux
opensuse / leap42.3
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
nodejs
node.js6.16.0
References & sources
- https://nodejs.org/en/blog/vulnerability/february-2019-security-releases/x_refsource_MISC
- http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00041.htmlvendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00046.htmlvendor-advisoryx_refsource_SUSE
- https://security.netapp.com/advisory/ntap-20190502-0008/x_refsource_CONFIRM
- https://security.gentoo.org/glsa/202003-48vendor-advisoryx_refsource_GENTOO
IDCVE-2019-5739