Description
All versions of Node.js 9.x and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of service (DoS) by causing a node process which provides an http server supporting TLS server to crash. This can be accomplished by sending duplicate/unexpected messages during the handshake. This vulnerability has been addressed by updating the TLS implementation.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-18904 | All versions of Node.js 9.x and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of service (DoS) by causing a node process which provides an http server supporting TLS server to crash. This can be accomplished by sending duplicate/unexpected messages during the handshake. This vulnerability has been addressed by updating the TLS implementation. |
References
History
No history.
Status: PUBLISHED
Assigner: nodejs
Published:
Updated: 2024-09-16T19:46:23.920Z
Reserved: 2018-02-15T00:00:00.000Z
Link: CVE-2018-7162
No data.
Status : Modified
Published: 2018-06-13T16:29:01.780
Modified: 2024-11-21T04:11:42.290
Link: CVE-2018-7162
OpenCVE Enrichment
No data.
EUVD