cbcvebase.
CVE-2020-8277
published 2020-11-19

CVE-2020-8277: A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versions < 15.2.1, <…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versions < 15.2.1, < 14.15.1, and < 12.19.1 by getting the application to resolve a DNS record with a larger number of responses. This is fixed in 15.2.1, 14.15.1, and 12.19.1.

Affected

35 ranges· showing 25
VendorProductVersion rangeFixed in
c-aresc-ares>= 0 < 1.17.1-11.17.1-1
c-aresc-ares>= 0 < 1.17.1-11.17.1-1
c-aresc-ares>= 0 < 1.17.1-11.17.1-1
c-aresc-ares>= 0 < 1.17.1-11.17.1-1
c-ares_projectc-ares< 1.16.01.16.0
debianc-ares< c-ares 1.17.1-1 (bookworm)c-ares 1.17.1-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
msrccbl2_python-gevent_21.1.2-3_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccm1_c-ares_1.17.1-1_on_cbl_mariner_1.0
nodejsnode>= 11.0 < 11.*11.*
nodejsnode>= 12.0 < 12.19.112.19.1
nodejsnode>= 13.0 < 13.*13.*
nodejsnode>= 14.0 < 14.15.114.15.1
nodejsnode>= 15.0 < 15.2.115.2.1
nodejsnode>= 4.0 < 4.*4.*
nodejsnode>= 5.0 < 5.*5.*
nodejsnode>= 6.0 < 6.*6.*
nodejsnode>= 7.0 < 7.*7.*
nodejsnode>= 8.0 < 8.*8.*
nodejsnode>= 9.0 < 9.*9.*
nodejsnode.js>= 12.16.3 < 12.19.112.19.1
nodejsnode.js>= 14.13.0 < 14.15.114.15.1

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH