CVE-2018-7161

🟡 Monitoruj

Błąd w http2 w Node.js umożliwia zdalne wywołanie awarii serwera.

CVSS
7.5
EPSS
7.8%
Exploit
none
Vendor
nodejs
Opis źródłowy (NVD)

All versions of Node.js 8.x, 9.x, and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of service (DoS) by causing a node server providing an http2 server to crash. This can be accomplished by interacting with the http2 server in a manner that triggers a cleanup bug where objects are used in native code after they are no longer available. This has been addressed by updating the http2 implementation.

dos Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS7.5
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)7.8%
Opublikowano (NVD)2018-06-13 16:29:01 UTC
Ostatnia modyfikacja (NVD)2026-10-08 22:16:47 UTC
Referencje