Lucene search

K
f5F5F5:K34369533
HistoryJun 15, 2018 - 12:00 a.m.

K34369533 : Node.js vulnerability CVE-2018-7161

2018-06-1500:00:00
my.f5.com
15

7.3 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

72.7%

Security Advisory Description

All versions of Node.js 8.x, 9.x, and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of service (DoS) by causing a node server providing an http2 server to crash. This can be accomplished by interacting with the http2 server in a manner that triggers a cleanup bug where objects are used in native code after they are no longer available. This has been addressed by updating the http2 implementation. (CVE-2018-7161)

Impact

There is no impact; F5 products are not affected by this vulnerability.