Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2024-22019

Published: February 16, 2024Last modified: May 22, 2024

Description

A vulnerability in Node.js HTTP servers allows an attacker to send a specially crafted HTTP request with chunked encoding, leading to resource exhaustion and denial of service (DoS). The server reads an unbounded number of bytes from a single connection, exploiting the lack of limitations on chunk extension bytes. The issue can cause CPU and network bandwidth exhaustion, bypassing standard safeguards like timeouts and body size limits.

Severity score breakdown

ParameterValue
Base score7.5
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactNONE
Availability impactHIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSnodejsFixed (18.19.1-r0)
StreamnodejsFixed (20.11.1-r0)
Liberica NIK23 (JDK 17)standard (nodejs)Fixed (23.0.4+1)
23 (JDK 21)standard (nodejs)Fixed (23.1.3+2)
24 (JDK 22)nodejsFixed (24.0.1+1)

References

Published BELL-SAs

ON THIS PAGE