nodejs: DoS with keep-alive HTTP connection
Published Mar 28, 2019
7.5
HIGHCVSS 3.1
EPSS 4.93%
Description
Keep-alive HTTP and HTTPS connections can remain open and inactive for up to 2 minutes in Node.js 6.16.0 and earlier. Node.js 8.0.0 introduced a dedicated server.keepAliveTimeout which defaults to 5 seconds. The behavior in Node.js 6.16.0 and earlier is a potential Denial of Service (DoS) attack vector. Node.js 6.17.0 introduces server.keepAliveTimeout and the 5-second default.
Affected products
-
- Version All versions prior to 6.17.0StatusaffectedConstraints-
- Version
No data.
Red Hat Enterprise Linux 8
nodejs:10/nodejs
Not affected
Red Hat OpenShift Container Platform 3.10
nodejs
Fix deferred
Red Hat OpenShift Container Platform 3.6
nodejs
Out of support scope
Red Hat OpenShift Container Platform 3.7
nodejs
Out of support scope
Red Hat OpenShift Container Platform 3.9
nodejs
Fix deferred
Red Hat Software Collections
rh-nodejs10-nodejs
Not affected
Red Hat Software Collections
rh-nodejs8-nodejs
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | nodejs:10/nodejs | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.10 | nodejs | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 3.6 | nodejs | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 3.7 | nodejs | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 3.9 | nodejs | Fix deferred | n/a |
| Red Hat Software Collections | rh-nodejs10-nodejs | Not affected | n/a |
| Red Hat Software Collections | rh-nodejs8-nodejs | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (9)
- http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00041.html vendor-advisoryx_refsource_SUSEThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00046.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-5739 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1690798 Issue Tracking
- https://nodejs.org/en/blog/vulnerability/february-2019-security-releases/ x_refsource_MISCVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-5739
- https://security.gentoo.org/glsa/202003-48 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://security.netapp.com/advisory/ntap-20190502-0008/ x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-5739
| Link | Providers | Tags |
|---|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00041.html | vendor-advisoryx_refsource_SUSEThird Party Advisory | |
| http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00046.html | vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2019-5739 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1690798 | Issue Tracking | |
| https://nodejs.org/en/blog/vulnerability/february-2019-security-releases/ | x_refsource_MISCVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-5739 | ||
| https://security.gentoo.org/glsa/202003-48 | vendor-advisoryx_refsource_GENTOOThird Party Advisory | |
| https://security.netapp.com/advisory/ntap-20190502-0008/ | x_refsource_CONFIRMThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2019-5739 |
Change history (0)
No recorded changes yet.