6.5
CVE-2024-22025
- EPSS 0.47%
- Veröffentlicht 19.03.2024 05:15:10
- Zuletzt bearbeitet 21.11.2024 08:55:25
- Quelle support@hackerone.com
- Teams Watchlist Login
- Unerledigt Login
A vulnerability in Node.js has been identified, allowing for a Denial of Service (DoS) attack through resource exhaustion when using the fetch() function to retrieve content from an untrusted URL. The vulnerability stems from the fact that the fetch() function in Node.js always decodes Brotli, making it possible for an attacker to cause resource exhaustion when fetching content from an untrusted URL. An attacker controlling the URL passed into fetch() can exploit this vulnerability to exhaust memory, potentially leading to process termination, depending on the system configuration.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerNodeJS
≫
Produkt
Node
Default Statusunaffected
Version <
4.*
Version
4.0
Status
affected
Version <
5.*
Version
5.0
Status
affected
Version <
6.*
Version
6.0
Status
affected
Version <
7.*
Version
7.0
Status
affected
Version <
8.*
Version
8.0
Status
affected
Version <
9.*
Version
9.0
Status
affected
Version <
10.*
Version
10.0
Status
affected
Version <
11.*
Version
11.0
Status
affected
Version <
12.*
Version
12.0
Status
affected
Version <
13.*
Version
13.0
Status
affected
Version <
14.*
Version
14.0
Status
affected
Version <
15.*
Version
15.0
Status
affected
Version <
16.*
Version
16.0
Status
affected
Version <
17.*
Version
17.0
Status
affected
Version <
18.19.1
Version
18.0
Status
affected
Version <
19.*
Version
19.0
Status
affected
Version <
20.11.1
Version
20.0
Status
affected
Version <
21.6.2
Version
21.0
Status
affected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.47% | 0.637 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
support@hackerone.com | 6.5 | 2.8 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
|
CWE-404 Improper Resource Shutdown or Release
The product does not release or incorrectly releases a resource before it is made available for re-use.