CVE-2020-8251
HIGH7.5EPSS 5.0%Published: 3/6/2024Modified: 4/3/2025
Description
Node.js < 14.11.0 is vulnerable to HTTP denial of service (DoS) attacks based on delayed requests submission which can make the server unable to accept new connections.
Affected packages (2)
- Bitnami/node>= 14.0.0, < 14.11.0
- Bitnami/node-min>= 14.0.0, < 14.11.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
References (6)
- WEBhttps://hackerone.com/reports/868834
- WEBhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4OOYAMJVLLCLXDTHW3V5UXNULZBBK4O6/
- WEBhttps://nodejs.org/en/blog/vulnerability/september-2020-security-releases/
- WEBhttps://nvd.nist.gov/vuln/detail/CVE-2020-8251
- WEBhttps://security.gentoo.org/glsa/202101-07
- WEBhttps://security.netapp.com/advisory/ntap-20201009-0004/