CVE-2018-7162

🟡 Monitoruj

Błąd w Node.js umożliwia atak DoS poprzez awarię serwera TLS.

CVSS
7.5
EPSS
6.9%
Exploit
none
Vendor
nodejs
Opis źródłowy (NVD)

All versions of Node.js 9.x and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of service (DoS) by causing a node process which provides an http server supporting TLS server to crash. This can be accomplished by sending duplicate/unexpected messages during the handshake. This vulnerability has been addressed by updating the TLS implementation.

dos Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS7.5
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)6.9%
Opublikowano (NVD)2018-06-13 16:29:01 UTC
Ostatnia modyfikacja (NVD)2026-10-08 22:16:47 UTC
Referencje