CVE-2017-14919
high-risk
Published 2017-10-30
Node.js before 4.8.5, 6.x before 6.11.5, and 8.x before 8.8.0 allows remote attackers to cause a denial of service (uncaught exception and crash) by leveraging a change in the zlib module 1.2.9 making 8 an invalid value for the windowBits parameter.
Do I need to act?
-
0.78% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.5/10
High
NETWORK
/ LOW complexity
Affected Products (20)
Affected Vendors
References (10)
Third Party Advisory
http://www.securityfocus.com/bid/101881
Vendor Advisory
https://nodejs.org/en/blog/release/v4.8.5/
Vendor Advisory
https://nodejs.org/en/blog/release/v6.11.5/
Vendor Advisory
https://nodejs.org/en/blog/release/v8.8.0/
Vendor Advisory
https://nodejs.org/en/blog/vulnerability/oct-2017-dos/
Third Party Advisory
http://www.securityfocus.com/bid/101881
Vendor Advisory
https://nodejs.org/en/blog/release/v4.8.5/
Vendor Advisory
https://nodejs.org/en/blog/release/v6.11.5/
Vendor Advisory
https://nodejs.org/en/blog/release/v8.8.0/
Vendor Advisory
https://nodejs.org/en/blog/vulnerability/oct-2017-dos/
50
/ 100
high-risk
Severity
26/34 · High
Exploitability
3/34 · Minimal
Exposure
21/34 · High