Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3886-1 | nodejs security update |
Debian DSA |
DSA-5991-1 | nodejs security update |
EUVD |
EUVD-2024-19625 | A vulnerability in Node.js HTTP servers allows an attacker to send a specially crafted HTTP request with chunked encoding, leading to resource exhaustion and denial of service (DoS). The server reads an unbounded number of bytes from a single connection, exploiting the lack of limitations on chunk extension bytes. The issue can cause CPU and network bandwidth exhaustion, bypassing standard safeguards like timeouts and body size limits. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 02 Apr 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Netapp
Netapp astra Control Center Nodejs Nodejs node.js |
|
| CPEs | cpe:2.3:a:netapp:astra_control_center:-:*:*:*:*:*:*:* cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:* |
|
| Vendors & Products |
Netapp
Netapp astra Control Center Nodejs Nodejs node.js |
Thu, 07 Nov 2024 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
ssvc
|
Tue, 05 Nov 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Node.js
Node.js node.js |
|
| Weaknesses | CWE-404 | |
| CPEs | cpe:2.3:a:node.js:node.js:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Node.js
Node.js node.js |
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2025-04-30T22:25:12.463Z
Reserved: 2024-01-04T01:04:06.574Z
Link: CVE-2024-22019
Updated: 2024-08-01T22:35:34.700Z
Status : Analyzed
Published: 2024-02-20T02:15:50.983
Modified: 2025-04-02T20:10:16.543
Link: CVE-2024-22019
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD