CVE-2021-22883
published 2021-03-03CVE-2021-22883: Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol'…
PriorityP258high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
77.39%
99.5th percentile
Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This leads to a leak of file descriptors. If a file descriptor limit is configured on the system, then the server is unable to accept new connections and prevent the process also from opening, e.g. a file. If no file descriptor limit is configured, then this lead to an excessive memory usage and cause the system to run out of memory.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nodejs | < nodejs 12.21.0~dfsg-1 (bookworm) | nodejs 12.21.0~dfsg-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| nodejs | node | >= 10.0 < 10.24.0 | 10.24.0 |
| nodejs | node | >= 11.0 < 11.* | 11.* |
| nodejs | node | >= 12.0 < 12.21.0 | 12.21.0 |
| nodejs | node | >= 13.0 < 13.* | 13.* |
| nodejs | node | >= 14.0 < 14.16.0 | 14.16.0 |
| nodejs | node | >= 15.0 < 15.10.0 | 15.10.0 |
| nodejs | node | >= 4.0 < 4.* | 4.* |
| nodejs | node | >= 5.0 < 5.* | 5.* |
| nodejs | node | >= 6.0 < 6.* | 6.* |
| nodejs | node | >= 7.0 < 7.* | 7.* |
| nodejs | node | >= 8.0 < 8.* | 8.* |
| nodejs | node | >= 9.0 < 9.* | 9.* |
| nodejs | node.js | >= 10.0.0 < 10.24.0 | 10.24.0 |
| nodejs | node.js | >= 12.0.0 < 12.21.0 | 12.21.0 |
| nodejs | node.js | >= 14.0.0 < 14.16.0 | 14.16.0 |
| nodejs | node.js | >= 15.0.0 < 15.10.0 | 15.10.0 |
| nodejs | nodejs | >= 0 < 12.21.0~dfsg-1 | 12.21.0~dfsg-1 |
| nodejs | nodejs | >= 0 < 12.21.0~dfsg-1 | 12.21.0~dfsg-1 |
| nodejs | nodejs | >= 0 < 12.21.0~dfsg-1 | 12.21.0~dfsg-1 |
| nodejs | nodejs | >= 0 < 12.21.0~dfsg-1 | 12.21.0~dfsg-1 |
| nodejs | nodejs | >= 0 < 10.19.0~dfsg-3ubuntu1.2 | 10.19.0~dfsg-3ubuntu1.2 |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect excessive connection attempts using 'unknownProtocol' against Node.js HTTP2 servers, which causes file descriptor leaks and potential DoS ↗
- →Monitor Node.js processes for abnormal file descriptor exhaustion or memory growth, which may indicate active exploitation of this DoS vulnerability ↗
- →Flag Node.js HTTP/2 servers running versions prior to 10.24.0, 12.21.0, 14.16.0, or 15.10.0 as vulnerable to this unknownProtocol DoS attack ↗
- ·No known public exploits specifically target this vulnerability as of the advisory date ↗
- ·Red Hat Enterprise Linux 9 package of nodejs is listed as Not Affected; Red Hat Quay 3 (quay/quay-rhel8) is listed as Will Not Fix — adjust detection scope accordingly ↗
- ·Red Hat Quay 3.3 and 3.2 are not impacted because they do not use Node.js as an HTTP server ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.5HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Node.js vulnerabilities
vendor_ubuntu·2023-10-05·CVSS 7.5
CVE-2021-22883 [HIGH] Node.js vulnerabilities
Title: Node.js vulnerabilities
Summary: Several security issues were fixed in Node.js.
It was discovered that Node.js incorrectly handled certain inputs. If a user
or an automated system were tricked into opening a specially crafted input
file, a remote attacker could possibly use this issue to cause a denial of
service. This issue was only fixed in Ubuntu 20.04 LTS. (CVE-2021-22883)
Vít Šesták discovered that Node.js incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to execute
arbitrary code. (CVE-2021-22884)
Instructions: In general, a standard system update will make all the necessary changes.
CISA ICS
Hitachi Energy e-mesh EMS
cisa_ics·2022-03-31·CVSS 8.1
[HIGH] Hitachi Energy e-mesh EMS
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Hitachi Energy e-mesh EMS
Last RevisedMarch 31, 2022
Alert CodeICSA-22-090-02
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Hitachi Energy
- Equipment: e-mesh EMS
- Vulnerabilities: Improper Restriction of Operations Within the Bounds of a Memory Buffer, Use After Free, Uncontrolled Resource Consumption
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could cause a denial-of-service condition.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following version of e-mesh EMS, an optimizer
CISA ICS
Siemens SINEC INS
cisa_ics·2022-03-10·CVSS 5.9
[MEDIUM] Siemens SINEC INS
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SINEC INS
Last RevisedMarch 10, 2022
Alert CodeICSA-22-069-09
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEC INS
- Vulnerability: Using Components with Known Vulnerabilities
## 2. RISK EVALUATION
Successful exploitation of this vulnerability in third-party components could allow an attacker to interfere with the affected product in various ways.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Siemens reports this vulnerability affects the following SINEC INS (Infrastructure Netw
Oracle
Oracle Oracle NoSQL Database Risk Matrix: Administration (Node.js) — CVE-2021-22883
vendor_oracle·2021-04-15·CVSS 7.5
CVE-2021-22883 [HIGH] Oracle Oracle NoSQL Database Risk Matrix: Administration (Node.js) — CVE-2021-22883
Oracle Oracle NoSQL Database Risk Matrix: Administration (Node.js) vulnerability
CVE: CVE-2021-22883
CVSS: 7.5
Protocol: Multiple
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2021 (APR 2021)
Red Hat
nodejs: HTTP2 'unknownProtocol' cause DoS by resource exhaustion
vendor_redhat·2021-02-20·CVSS 7.5
CVE-2021-22883 [HIGH] CWE-400 nodejs: HTTP2 'unknownProtocol' cause DoS by resource exhaustion
nodejs: HTTP2 'unknownProtocol' cause DoS by resource exhaustion
Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This leads to a leak of file descriptors. If a file descriptor limit is configured on the system, then the server is unable to accept new connections and prevent the process also from opening, e.g. a file. If no file descriptor limit is configured, then this lead to an excessive memory usage and cause the system to run out of memory.
A flaw was found in nodejs. When too many connection attempts with an 'unknownProtocol' are established a leak of file descriptors can occur leading to a potential denial of service. If a file descriptor limit is configure
Debian
CVE-2021-22883: nodejs - Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial ...
vendor_debian·2021·CVSS 7.5
CVE-2021-22883 [HIGH] CVE-2021-22883: nodejs - Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial ...
Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This leads to a leak of file descriptors. If a file descriptor limit is configured on the system, then the server is unable to accept new connections and prevent the process also from opening, e.g. a file. If no file descriptor limit is configured, then this lead to an excessive memory usage and cause the system to run out of memory.
Scope: local
bookworm: resolved (fixed in 12.21.0~dfsg-1)
bullseye: resolved (fixed in 12.21.0~dfsg-1)
forky: resolved (fixed in 12.21.0~dfsg-1)
sid: resolved (fixed in 12.21.0~dfsg-1)
trixie: resolved (fixed in 12.21.0~dfsg-1)
OSV
nodejs vulnerabilities
osv·2023-10-05·CVSS 7.5
CVE-2021-22883 [HIGH] nodejs vulnerabilities
nodejs vulnerabilities
It was discovered that Node.js incorrectly handled certain inputs. If a user
or an automated system were tricked into opening a specially crafted input
file, a remote attacker could possibly use this issue to cause a denial of
service. This issue was only fixed in Ubuntu 20.04 LTS. (CVE-2021-22883)
Vít Šesták discovered that Node.js incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to execute
arbitrary code. (CVE-2021-22884)
GHSA
GHSA-mjgw-69fr-p4h2: Node
ghsa_unreviewed·2022-05-24
CVE-2021-22883 [HIGH] CWE-400 GHSA-mjgw-69fr-p4h2: Node
Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This leads to a leak of file descriptors. If a file descriptor limit is configured on the system, then the server is unable to accept new connections and prevent the process also from opening, e.g. a file. If no file descriptor limit is configured, then this lead to an excessive memory usage and cause the system to run out of memory.
OSV
CVE-2021-22883: Node
osv·2021-03-03·CVSS 7.5
CVE-2021-22883 [HIGH] CVE-2021-22883: Node
Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This leads to a leak of file descriptors. If a file descriptor limit is configured on the system, then the server is unable to accept new connections and prevent the process also from opening, e.g. a file. If no file descriptor limit is configured, then this lead to an excessive memory usage and cause the system to run out of memory.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdfhttps://hackerone.com/reports/1043360https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E4FRS5ZVK4ZQ7XIJQNGIKUXG2DJFHLO7/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F45Y7TXSU33MTKB6AGL2Q5V5ZOCNPKOG/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HSYFUGKFUSZ27M5TEZ3FKILWTWFJTFAZ/https://nodejs.org/en/blog/vulnerability/february-2021-security-releases/https://security.netapp.com/advisory/ntap-20210416-0001/https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdfhttps://hackerone.com/reports/1043360https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E4FRS5ZVK4ZQ7XIJQNGIKUXG2DJFHLO7/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F45Y7TXSU33MTKB6AGL2Q5V5ZOCNPKOG/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HSYFUGKFUSZ27M5TEZ3FKILWTWFJTFAZ/https://nodejs.org/en/blog/vulnerability/february-2021-security-releases/https://security.netapp.com/advisory/ntap-20210416-0001/https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2021-03-03
Published