A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versions < 15.2.1, < 14.15.1, and < 12.19.1 by getting the application to resolve a DNS record with a larger number of responses. This is fixed in 15.2.1, 14.15.1, and 12.19.1.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: hackerone
Published: 2020-11-19T00:32:13
Updated: 2024-08-04T09:56:28.290Z
Reserved: 2020-01-28T00:00:00
Link: CVE-2020-8277
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-11-19T01:15:12.763
Modified: 2023-11-07T03:26:19.410
Link: CVE-2020-8277
Redhat