CVE-2013-4450
published 2013-10-21CVE-2013-4450: The HTTP server in Node.js 0.10.x before 0.10.21 and 0.8.x before 0.8.26 allows remote attackers to cause a denial of service (memory and CPU consumption) by…
PriorityP338medium5CVSS 2.0
AVNACLAuNCNINAP
EXPLOIT
EPSS
37.22%
98.4th percentile
The HTTP server in Node.js 0.10.x before 0.10.21 and 0.8.x before 0.8.26 allows remote attackers to cause a denial of service (memory and CPU consumption) by sending a large number of pipelined requests without reading the response.
Affected
52 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nodejs | < nodejs 0.10.21~dfsg1-1 (bookworm) | nodejs 0.10.21~dfsg1-1 (bookworm) |
| nodejs | nodejs | — | — |
| nodejs | nodejs | — | — |
| nodejs | nodejs | — | — |
| nodejs | nodejs | — | — |
| nodejs | nodejs | — | — |
| nodejs | nodejs | — | — |
| nodejs | nodejs | — | — |
| nodejs | nodejs | — | — |
| nodejs | nodejs | — | — |
| nodejs | nodejs | — | — |
| nodejs | nodejs | — | — |
| nodejs | nodejs | — | — |
| nodejs | nodejs | — | — |
| nodejs | nodejs | — | — |
| nodejs | nodejs | — | — |
| nodejs | nodejs | — | — |
| nodejs | nodejs | — | — |
| nodejs | nodejs | — | — |
| nodejs | nodejs | — | — |
| nodejs | nodejs | — | — |
| nodejs | nodejs | — | — |
| nodejs | nodejs | — | — |
| nodejs | nodejs | — | — |
| nodejs | nodejs | — | — |
Detection & IOCsextracted from sources · hover to see the quote
urlhttps://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/dos/http/nodejs_pipelining.rb↗
- →The attack sends many pipelined HTTP requests on a single TCP connection without reading responses, causing unbounded memory and CPU growth on the Node.js process. Monitor for a single source IP opening one connection and issuing an abnormally large number of pipelined HTTP requests. ↗
- →Vulnerable Node.js versions are 0.10.x before 0.10.21 and 0.8.x before 0.8.26. Identify these versions in your environment as they are exploitable targets. ↗
- →The fix introduced backpressure in the HTTP pipeline handler ('http: provide backpressure for pipeline flood'). Absence of this patch in Node.js 0.10.x/0.8.x source or binaries confirms vulnerability. ↗
- ·OpenShift Enterprise 1.2 (and its nodejs 0.6.x) will NOT receive a fix as the issue is rated Moderate and the product is past its full-support lifecycle phase. ↗
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
NodeJS: HTTP Pipelining DoS
vendor_redhat·2013-10-18·CVSS 5.0
CVE-2013-4450 [MEDIUM] NodeJS: HTTP Pipelining DoS
NodeJS: HTTP Pipelining DoS
The HTTP server in Node.js 0.10.x before 0.10.21 and 0.8.x before 0.8.26 allows remote attackers to cause a denial of service (memory and CPU consumption) by sending a large number of pipelined requests without reading the response.
Statement: OpenShift Enterprise 1.2 is in a lifecycle phase that only provides Critical and Important security updates, as this issue is rated Moderate this issue will not be fixed. For additional information, refer to the Red Hat OpenShift Enterprise Life Cycle: https://access.redhat.com/support/policy/updates/openshift.
Package: nodejs (OpenShift Enterprise 1) - Affected
Debian
CVE-2013-4450: nodejs - The HTTP server in Node.js 0.10.x before 0.10.21 and 0.8.x before 0.8.26 allows ...
vendor_debian·2013·CVSS 5.0
CVE-2013-4450 [MEDIUM] CVE-2013-4450: nodejs - The HTTP server in Node.js 0.10.x before 0.10.21 and 0.8.x before 0.8.26 allows ...
The HTTP server in Node.js 0.10.x before 0.10.21 and 0.8.x before 0.8.26 allows remote attackers to cause a denial of service (memory and CPU consumption) by sending a large number of pipelined requests without reading the response.
Scope: local
bookworm: resolved (fixed in 0.10.21~dfsg1-1)
bullseye: resolved (fixed in 0.10.21~dfsg1-1)
forky: resolved (fixed in 0.10.21~dfsg1-1)
sid: resolved (fixed in 0.10.21~dfsg1-1)
trixie: resolved (fixed in 0.10.21~dfsg1-1)
GHSA
GHSA-qf9f-226q-7q59: The HTTP server in Node
ghsa_unreviewed·2022-05-14
CVE-2013-4450 [MEDIUM] CWE-20 GHSA-qf9f-226q-7q59: The HTTP server in Node
The HTTP server in Node.js 0.10.x before 0.10.21 and 0.8.x before 0.8.26 allows remote attackers to cause a denial of service (memory and CPU consumption) by sending a large number of pipelined requests without reading the response.
OSV
CVE-2013-4450: The HTTP server in Node
osv·2013-10-21·CVSS 5.0
CVE-2013-4450 [MEDIUM] CVE-2013-4450: The HTTP server in Node
The HTTP server in Node.js 0.10.x before 0.10.21 and 0.8.x before 0.8.26 allows remote attackers to cause a denial of service (memory and CPU consumption) by sending a large number of pipelined requests without reading the response.
No detection rules found.
Bugzilla
CVE-2013-4450 NodeJS: HTTP Pipelining DoS [fedora-all]
bugzilla·2013-10-20·CVSS 5.0
CVE-2013-4450 [MEDIUM] CVE-2013-4450 NodeJS: HTTP Pipelining DoS [fedora-all]
CVE-2013-4450 NodeJS: HTTP Pipelining DoS [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects multiple supported
Bugzilla
CVE-2013-4450 NodeJS: HTTP Pipelining DoS [epel-6]
bugzilla·2013-10-20·CVSS 5.0
CVE-2013-4450 [MEDIUM] CVE-2013-4450 NodeJS: HTTP Pipelining DoS [epel-6]
CVE-2013-4450 NodeJS: HTTP Pipelining DoS [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-6 tracking bug for nodejs: see blocks bug li
Bugzilla
CVE-2013-4450 NodeJS: HTTP Pipelining DoS
bugzilla·2013-10-20·CVSS 5.0
CVE-2013-4450 [MEDIUM] CVE-2013-4450 NodeJS: HTTP Pipelining DoS
CVE-2013-4450 NodeJS: HTTP Pipelining DoS
Timothy J Fontaine of the NodeJS reports the following security issue:
This release contains a security fix for the http server implementation, please
upgrade as soon as possible. Details will be released soon.
2013.10.18, Version 0.10.21 (Stable)
* http: provide backpressure for pipeline flood (isaacs)
https://groups.google.com/forum/#!topic/nodejs/NEbweYB0ei0
https://github.com/joyent/node/issues/6214
https://github.com/joyent/node/commit/085dd30e93da67362f044ad1b3b6b2d997064692
Fixed upstream in version 0.10.21 and 0.8.26:
http://blog.nodejs.org/2013/10/18/node-v0-10-21-stable/
http://blog.nodejs.org/2013/10/18/node-v0-8-26-maintenance/
Discussion:
Created nodejs tracking bugs for this issue:
Affects: fedora-all [bug 1021171]
Affects:
http://blog.nodejs.org/2013/10/18/node-v0-10-21-stable/http://blog.nodejs.org/2013/10/18/node-v0-8-26-maintenance/http://lists.opensuse.org/opensuse-updates/2013-12/msg00051.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1842.htmlhttp://www.openwall.com/lists/oss-security/2013/10/20/1http://www.securityfocus.com/bid/63229https://github.com/joyent/node/issues/6214https://github.com/rapid7/metasploit-framework/pull/2548https://groups.google.com/forum/#%21topic/nodejs/NEbweYB0ei0https://kb.juniper.net/JSA10783http://blog.nodejs.org/2013/10/18/node-v0-10-21-stable/http://blog.nodejs.org/2013/10/18/node-v0-8-26-maintenance/http://lists.opensuse.org/opensuse-updates/2013-12/msg00051.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1842.htmlhttp://www.openwall.com/lists/oss-security/2013/10/20/1http://www.securityfocus.com/bid/63229https://github.com/joyent/node/issues/6214https://github.com/rapid7/metasploit-framework/pull/2548https://groups.google.com/forum/#%21topic/nodejs/NEbweYB0ei0https://kb.juniper.net/JSA10783
2013-10-21
Published