Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:44453
HistoryNov 29, 2023 - 5:49 a.m.

Denial Of Service (DoS)

2023-11-2905:49:59
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
19
nodejs
vulnerability
x509 certificate
dos
attacks
crypto api
termination

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

30.0%

nodejs is vulnerable to Denial Of Service (DoS). The vulnerability exists when an invalid public key is used to create an x509 certificate using the crypto.X509Certificate() API. A non-expected termination occurs, making it susceptible to Denial of Service (DoS) attacks. In this scenario, an attacker could force interruptions of application processing, as the process terminates when accessing public key info of provided certificates from user code. This results in the loss of the current context of users, causing a DoS scenario.

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

30.0%