Denial of Service Vulnerability in Node.js HTTP/2 Server
CVE-2018-7161

7.5HIGH

Key Information:

Status
Vendor
CVE Published:
13 June 2018

What is CVE-2018-7161?

A vulnerability exists in all versions of Node.js 8.x, 9.x, and 10.x that can enable attackers to perform a Denial of Service (DoS) attack. The issue arises when interacting with an HTTP/2 server in a way that triggers a cleanup bug, resulting in a crash of the node server. This occurs due to the improper handling of objects in the native code after they have been released. The vulnerability has been addressed with updates to the HTTP/2 implementation. It is crucial for users to upgrade to the latest versions to safeguard their applications.

Affected Version(s)

Node.js 8.x+

Node.js 9.x+

Node.js 10.x+

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2018-7161 : Denial of Service Vulnerability in Node.js HTTP/2 Server