7.5

CVE-2018-12122

Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Slowloris HTTP Denial of Service: An attacker can cause a Denial of Service (DoS) by sending headers very slowly keeping HTTP or HTTPS connections and associated resources alive for a long period of time.

Data is provided by the National Vulnerability Database (NVD)
NodejsNode.Js SwEditionlts Version >= 6.0.0 < 6.15.1
NodejsNode.Js SwEditionlts Version >= 8.0.0 < 8.14.0
NodejsNode.Js SwEditionlts Version >= 10.0.0 < 10.14.0
NodejsNode.Js SwEdition- Version >= 11.0.0 < 11.3.0
SuseSuse Openstack Cloud Version7
SuseSuse Openstack Cloud Version8
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 2.81% 0.856
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.