← All CVEs

CVE-2020-8277

high · 7.5

A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versions < 15.2.1, < 14.15.1, and < 12.19.1 by getting the application to resolve a DNS record with a larger number of responses. This is fixed in 15.2.1, 14.15.1, and 12.19.1.

7.5
CVSS
54.2%
EPSS (exploit prob.)
99th
EPSS percentile
2020-11-19
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses

CWE-400

Affected products

VendorProductAffected versions
nodejsnode.js>= 12.16.3, < 12.19.1
nodejsnode.js>= 14.13.0, < 14.15.1
nodejsnode.js>= 15.0.0, < 15.2.1
fedoraprojectfedora32
fedoraprojectfedora33
oracleblockchain_platform< 21.1.2
oraclegraalvm19.3.4
oraclegraalvm20.3.0
oraclejd_edwards_enterpriseone_tools< 9.2.6.0
oraclemysql_cluster<= 8.0.23
oracleretail_xstore_point_of_service16.0.6
oracleretail_xstore_point_of_service17.0.4
oracleretail_xstore_point_of_service18.0.3
oracleretail_xstore_point_of_service19.0.2
c-ares_projectc-ares< 1.16.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2020-8277