CVE-2018-12122

Description

Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Slowloris HTTP Denial of Service: An attacker can cause a Denial of Service (DoS) by sending headers very slowly keeping HTTP or HTTPS connections and associated resources alive for a long period of time.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
3.643

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2019-5737,CVE-2018-12122,CVE-2019-5739,CVE-2019-1559 are fixed in Node.js (11.15.0)Windows
Multiple vulnerabilities are fixed in Node.js (11.15.0)Windows
Vulnerabilities CVE-2019-5737,CVE-2018-12122,CVE-2019-5739,CVE-2019-1559 are fixed in Node.js (x64)(11.15.0)Windows
Multiple vulnerabilities are fixed in Node.js (x64)(11.15.0)Windows
Vulnerabilities CVE-2019-5737,CVE-2018-12122,CVE-2019-5739,CVE-2019-1559 are fixed in Node.js (x64) (10.15.2)Windows
Vulnerabilities CVE-2019-5737,CVE-2018-12122,CVE-2019-5739,CVE-2019-1559 are fixed in Node.js (10.15.2)Windows
Vulnerabilities CVE-2019-5737,CVE-2018-12122,CVE-2019-5739,CVE-2019-1559 are fixed in Node.js 10 (10.24.1)Windows
Vulnerabilities CVE-2019-5737,CVE-2018-12122,CVE-2019-5739,CVE-2019-1559 are fixed in Node.js 16 (x64) (16.17.0)Windows
Vulnerabilities CVE-2019-5737,CVE-2018-12122,CVE-2019-5739,CVE-2019-1559 are fixed in Node.js 16 (16.17.0)Windows
Multiple vulnerabilities are fixed in Node.js 10 (10.24.1)Windows
Multiple vulnerabilities are fixed in Node.js 16 (x64) (16.15.0)Windows
Multiple vulnerabilities are fixed in Node.js 16 (16.15.0)Windows
Multiple vulnerabilities are fixed in Node.js 10 (x64) (10.24.1)Windows
Vulnerabilities CVE-2019-5737,CVE-2018-12122,CVE-2019-5739,CVE-2019-1559 are fixed in Node.js 8 8.15.1Windows
Multiple vulnerabilities are fixed in Node.js 8 8.14.0Windows
Vulnerabilities CVE-2019-5737,CVE-2018-12122,CVE-2019-5739,CVE-2019-1559 are fixed in Node.js 8 (x64) 8.15.1Windows
Multiple vulnerabilities are fixed in Node.js 8 (x64) 8.14.0Windows
Multiple Vulnerabilities are affected in IBM Planning Analytics Local 2.0Windows
Uncontrolled Resource Consumption Vulnerability (CVE-2018-12122)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-309917Node.js (11.15.0)
PATCH-309917Node.js (11.15.0)
PATCH-309918Node.js (x64)(11.15.0)
PATCH-309918Node.js (x64)(11.15.0)
PATCH-319043Node.js 10 (x64) (10.24.1)
PATCH-319042Node.js 10 (10.24.1)
PATCH-319042Node.js 10 (10.24.1)
PATCH-332182Node.js 16 (x64) (16.20.2)
PATCH-332181Node.js 16 (16.20.2)
PATCH-319042Node.js 10 (10.24.1)
PATCH-332182Node.js 16 (x64) (16.20.2)
PATCH-332181Node.js 16 (16.20.2)
PATCH-319043Node.js 10 (x64) (10.24.1)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234