Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This leads to a leak of file descriptors. If a file descriptor limit is configured on the system, then the server is unable to accept new connections and prevent the process also from opening, e.g. a file. If no file descriptor limit is configured, then this lead to an excessive memory usage and cause the system to run out of memory.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
History
24 Oct 2022, 17:05
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-772 |
06 Apr 2022, 16:28
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://nodejs.org/en/blog/vulnerability/february-2021-security-releases/ - Patch, Release Notes, Vendor Advisory | |
References | (CONFIRM) https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf - Patch, Third Party Advisory | |
CPE | cpe:2.3:a:siemens:sinec_infrastructure_network_services:*:*:*:*:*:*:*:* |
10 Mar 2022, 17:41
Type | Values Removed | Values Added |
---|---|---|
References |
|
08 Dec 2021, 20:16
Type | Values Removed | Values Added |
---|---|---|
References | (N/A) https://www.oracle.com//security-alerts/cpujul2021.html - Patch, Third Party Advisory | |
References | (MISC) https://www.oracle.com/security-alerts/cpuoct2021.html - Patch, Third Party Advisory | |
CPE | cpe:2.3:a:oracle:mysql_cluster:*:*:*:*:*:*:*:* cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.59:*:*:*:*:*:*:* cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:* cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:*:*:*:*:*:*:*:* |
20 Oct 2021, 11:16
Type | Values Removed | Values Added |
---|---|---|
References |
|
16 Jun 2021, 14:02
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:oracle:graalvm:20.3.1.2:*:*:*:enterprise:*:*:* cpe:2.3:a:oracle:graalvm:19.3.5:*:*:*:enterprise:*:*:* cpe:2.3:a:netapp:e-series_performance_analyzer:-:*:*:*:*:*:*:* cpe:2.3:a:oracle:nosql_database:*:*:*:*:*:*:*:* cpe:2.3:a:oracle:graalvm:21.0.0.2:*:*:*:enterprise:*:*:* |
|
References | (MISC) https://www.oracle.com/security-alerts/cpuApr2021.html - Patch, Third Party Advisory | |
References | (CONFIRM) https://security.netapp.com/advisory/ntap-20210416-0001/ - Third Party Advisory |
14 Jun 2021, 18:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
Information
Published : 2021-03-03 18:15
Updated : 2024-02-04 21:23
NVD link : CVE-2021-22883
Mitre link : CVE-2021-22883
CVE.ORG link : CVE-2021-22883
JSON object : View
Products Affected
oracle
- jd_edwards_enterpriseone_tools
- nosql_database
- mysql_cluster
- peoplesoft_enterprise_peopletools
- graalvm
netapp
- e-series_performance_analyzer
nodejs
- node.js
siemens
- sinec_infrastructure_network_services
fedoraproject
- fedora