CVE-2021-22883
high · 7.5Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This leads to a leak of file descriptors. If a file descriptor limit is configured on the system, then the server is unable to accept new connections and prevent the process also from opening, e.g. a file. If no file descriptor limit is configured, then this lead to an excessive memory usage and cause the system to run out of memory.
7.5
CVSS
74.4%
EPSS (exploit prob.)
99th
EPSS percentile
2021-03-03
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses
CWE-400CWE-772
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| nodejs | node.js | >= 10.0.0, < 10.24.0 |
| nodejs | node.js | >= 12.0.0, < 12.21.0 |
| nodejs | node.js | >= 14.0.0, < 14.16.0 |
| nodejs | node.js | >= 15.0.0, < 15.10.0 |
| fedoraproject | fedora | 32 |
| fedoraproject | fedora | 33 |
| fedoraproject | fedora | 34 |
| netapp | e-series_performance_analyzer | all versions |
| oracle | graalvm | 19.3.5 |
| oracle | graalvm | 20.3.1.2 |
| oracle | graalvm | 21.0.0.2 |
| oracle | jd_edwards_enterpriseone_tools | < 9.2.6.0 |
| oracle | mysql_cluster | <= 8.0.25 |
| oracle | nosql_database | < 20.3 |
| oracle | peoplesoft_enterprise_peopletools | 8.58 |
| oracle | peoplesoft_enterprise_peopletools | 8.59 |
| siemens | sinec_infrastructure_network_services | < 1.0.1.1 |
Check a specific version with /api/v1/cve/match.
References
- https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf
- https://hackerone.com/reports/1043360
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E4FRS5ZVK4ZQ7XIJQNGIKUXG2DJFHLO7/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F45Y7TXSU33MTKB6AGL2Q5V5ZOCNPKOG/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HSYFUGKFUSZ27M5TEZ3FKILWTWFJTFAZ/
- https://nodejs.org/en/blog/vulnerability/february-2021-security-releases/
- https://security.netapp.com/advisory/ntap-20210416-0001/
- https://www.oracle.com//security-alerts/cpujul2021.html
- https://www.oracle.com/security-alerts/cpuApr2021.html
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf
- https://hackerone.com/reports/1043360
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E4FRS5ZVK4ZQ7XIJQNGIKUXG2DJFHLO7/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F45Y7TXSU33MTKB6AGL2Q5V5ZOCNPKOG/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HSYFUGKFUSZ27M5TEZ3FKILWTWFJTFAZ/
- https://nodejs.org/en/blog/vulnerability/february-2021-security-releases/
- https://security.netapp.com/advisory/ntap-20210416-0001/
- https://www.oracle.com//security-alerts/cpujul2021.html
- https://www.oracle.com/security-alerts/cpuApr2021.html
- https://www.oracle.com/security-alerts/cpuoct2021.html
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2021-22883