7.8

CVE-2021-22883

Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This leads to a leak of file descriptors. If a file descriptor limit is configured on the system, then the server is unable to accept new connections and prevent the process also from opening, e.g. a file. If no file descriptor limit is configured, then this lead to an excessive memory usage and cause the system to run out of memory.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Nodejs ≫ Node.Js SwEdition lts Version >= 10.0.0 < 10.24.0
Nodejs ≫ Node.Js SwEdition lts Version >= 12.0.0 < 12.21.0
Nodejs ≫ Node.Js SwEdition lts Version >= 14.0.0 < 14.16.0
Nodejs ≫ Node.Js SwEdition - Version >= 15.0.0 < 15.10.0
Fedoraproject ≫ Fedora Version 32
Fedoraproject ≫ Fedora Version 33
Fedoraproject ≫ Fedora Version 34
Oracle ≫ Graalvm Version 19.3.5 SwEdition enterprise
Oracle ≫ Graalvm Version 20.3.1.2 SwEdition enterprise
Oracle ≫ Graalvm Version 21.0.0.2 SwEdition enterprise
Oracle ≫ Jd Edwards Enterpriseone Tools Version < 9.2.6.0
Oracle ≫ Mysql Cluster Version <= 8.0.25
Oracle ≫ Nosql Database Version < 20.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 74.35% 0.994
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource.

CWE-772 Missing Release of Resource after Effective Lifetime

The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.

https://www.oracle.com//security-alerts/cpujul2021.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2021.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpuApr2021.html
Patch
Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf
Patch
Third Party Advisory
https://hackerone.com/reports/1043360
Third Party Advisory
Permissions Required
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E4FRS5ZVK4ZQ7XIJQNGIKUXG2DJFHLO7/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F45Y7TXSU33MTKB6AGL2Q5V5ZOCNPKOG/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HSYFUGKFUSZ27M5TEZ3FKILWTWFJTFAZ/
https://nodejs.org/en/blog/vulnerability/february-2021-security-releases/
Patch
Vendor Advisory
Release Notes
https://security.netapp.com/advisory/ntap-20210416-0001/
Third Party Advisory