Lucene search

K
cvelistNodejsCVELIST:CVE-2018-7162
HistoryJun 12, 2018 - 12:00 a.m.

CVE-2018-7162

2018-06-1200:00:00
nodejs
www.cve.org

7.2 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

72.7%

All versions of Node.js 9.x and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of service (DoS) by causing a node process which provides an http server supporting TLS server to crash. This can be accomplished by sending duplicate/unexpected messages during the handshake. This vulnerability has been addressed by updating the TLS implementation.

CNA Affected

[
  {
    "product": "Node.js",
    "vendor": "The Node.js Project",
    "versions": [
      {
        "status": "affected",
        "version": "9.x+"
      },
      {
        "status": "affected",
        "version": "10.x+"
      }
    ]
  }
]