← Back

CVE-2018-12121

nvd nist
Published: Nov 28, 2018Modified: Dec 27, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Denial of Service with large HTTP headers: By using a combination of many requests with maximum sized headers (almost 80 KB per connection), and carefully timed completion of the headers, it is possible to cause the HTTP server to abort from heap allocation failure. Attack potential is mitigated by the use of a load balancer or other proxy layer.

Affected (18)

1 product
Node.js
7 products
Enterprise Linux
Enterprise Linux Desktop
Enterprise Linux Eus
Enterprise Linux Server
Enterprise Linux Server Aus
Enterprise Linux Server Tus
Enterprise Linux Workstation
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Nodejs
From 11.0.0 to 11.3.0
From 10.0.0 to 10.14.0
From 6.0.0 to 6.15.0
From 8.0.0 to 8.14.0
Configuration B
14 vulnerable

References (13)

Source: cve-request@iojs.org
Third Party AdvisoryVDB Entry
Source: cve-request@iojs.org
Third Party Advisory
Source: cve-request@iojs.org
Third Party Advisory
Source: cve-request@iojs.org
Third Party Advisory
Source: cve-request@iojs.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.