Back

HIGH

nodejs: Debugger port 5858 listens on any interface by default

Published Nov 28, 2018

Description

Node.js: All versions prior to Node.js 6.15.0: Debugger port 5858 listens on any interface by default: When the debugger is enabled with `node --debug` or `node debug`, it listens to port 5858 on all interfaces by default. This may allow remote computers to attach to the debug port and evaluate arbitrary JavaScript. The default interface is now localhost. It has always been possible to start the debugger on a specific interface, such as `node --debug=localhost`. The debugger was removed in Node.js 8 and replaced with the inspector, so no versions from 8 and later are vulnerable.

Affected products

Remediation

Red Hat statement

The nodejs RPMs shipped in Red Hat OpenShift Container Platform (OCP) versions 3.6 through 3.10 are vulnerable to this flaw because they contain the affected code. Later versions of OCP used nodejs RPMs delivered from Red Hat Software Collections and Red Hat Enterprise Linux channels.

Red Hat mitigation

* On any version : Ensure the firewall prevents access to port 5858 on untrusted interfaces. * On nodejs 6 : To enforce the debug on a specific interface: $ node --debug=localhost

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner nodejs
Published Nov 28, 2018
Updated Aug 5, 2024
Reserved Jun 11, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Nov 27, 2018