Back

HIGH

nodejs: Slowloris HTTP Denial of Service

Published Nov 28, 2018

Description

Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Slowloris HTTP Denial of Service: An attacker can cause a Denial of Service (DoS) by sending headers very slowly keeping HTTP or HTTPS connections and associated resources alive for a long period of time.

Affected products

Remediation

Red Hat statement

The nodejs RPMs shipped in Red Hat OpenShift Container Platform (OCP) versions 3.6 through 3.10 are vulnerable to this flaw because they contain the affected code. Later versions of OCP used nodejs RPMs delivered from Red Hat Software Collections and Red Hat Enterprise Linux channels.

Red Hat mitigation

The use of a Load Balancer or a Reverse Proxy will increase the difficulty of the attack.

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner nodejs
Published Nov 28, 2018
Updated Dec 13, 2024
Reserved Jun 11, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Nov 27, 2018