cbcvebase.
CVE-2020-8277
published 2020-11-19

CVE-2020-8277: A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versions < 15.2.1, <…

PriorityP355high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
54.16%
98.9th percentile
A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versions < 15.2.1, < 14.15.1, and < 12.19.1 by getting the application to resolve a DNS record with a larger number of responses. This is fixed in 15.2.1, 14.15.1, and 12.19.1.

Affected

35 ranges· showing 25
VendorProductVersion rangeFixed in
c-aresc-ares>= 0 < 1.17.1-11.17.1-1
c-aresc-ares>= 0 < 1.17.1-11.17.1-1
c-aresc-ares>= 0 < 1.17.1-11.17.1-1
c-aresc-ares>= 0 < 1.17.1-11.17.1-1
c-ares_projectc-ares< 1.16.01.16.0
debianc-ares< c-ares 1.17.1-1 (bookworm)c-ares 1.17.1-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
msrccbl2_python-gevent_21.1.2-3_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccm1_c-ares_1.17.1-1_on_cbl_mariner_1.0
nodejsnode>= 11.0 < 11.*11.*
nodejsnode>= 12.0 < 12.19.112.19.1
nodejsnode>= 13.0 < 13.*13.*
nodejsnode>= 14.0 < 14.15.114.15.1
nodejsnode>= 15.0 < 15.2.115.2.1
nodejsnode>= 4.0 < 4.*4.*
nodejsnode>= 5.0 < 5.*5.*
nodejsnode>= 6.0 < 6.*6.*
nodejsnode>= 7.0 < 7.*7.*
nodejsnode>= 8.0 < 8.*8.*
nodejsnode>= 9.0 < 9.*9.*
nodejsnode.js>= 12.16.3 < 12.19.112.19.1
nodejsnode.js>= 14.13.0 < 14.15.114.15.1

Detection & IOCsextracted from sources · hover to see the quote

  • Trigger condition: attacker causes the Node.js application to resolve a DNS record with a larger number of responses, exploiting insufficient naddrttls validation in c-ares ares_parse_{a,aaaa}_reply()
  • Vulnerable component is c-ares library functions ares_parse_a_reply() and ares_parse_aaaa_reply() — monitor for abnormally large DNS response answer counts processed by these functions
  • Attack vector is network/remote over HTTP; flag Node.js applications that allow user-controlled DNS resolution targets as high-risk attack surface
  • ·Fixed versions for Node.js are 15.2.1, 14.15.1, and 12.19.1 — any Node.js deployment below these versions remains vulnerable
  • ·Red Hat Enterprise Linux 5/6/7/8 standalone c-ares packages are NOT affected; only Node.js bundled c-ares is the concern
  • ·Debian fixed version for c-ares is 1.17.1-1 across bookworm, bullseye, forky, sid, and trixie

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.