[FREEBSD:AD792169-2AA4-11EB-AB71-0022489AD614] Node.js -- November 2020 Security Releases
Severity
High
Affected Packages
3
CVEs
1
Node.js reports:
Updates are now available for v12.x, v14.x and v15.x Node.js release lines for the following issues.
Denial of Service through DNS request (CVE-2020-8277)
A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of service by getting the application to resolve a DNS record with a larger number of responses.
Package | Affected Version |
---|---|
pkg:freebsd/node14 | < 14.15.1 |
pkg:freebsd/node12 | < 12.19.1 |
pkg:freebsd/node | < 15.2.1 |
- ID
- FREEBSD:AD792169-2AA4-11EB-AB71-0022489AD614
- Severity
- high
- Severity from
- CVE-2020-8277
- URL
- http://vuxml.freebsd.org/freebsd/ad792169-2aa4-11eb-ab71-0022489ad614.html
- Published
-
2020-11-16T00:00:00
(3 years ago) - Modified
-
2020-11-21T00:00:00
(3 years ago) - Rights
- FreeBSD VuXML Security Team
- Other Advisories
-
- ALPINE:CVE-2020-8277
- ALSA-2020:5499
- ALSA-2021:0551
- ASA-202011-18
- ELSA-2020-5499
- ELSA-2021-0551
- FEDORA-2020-307e873389
- FEDORA-2020-7473744de1
- FEDORA-2021-afed2b904e
- FEDORA-2021-ee913722db
- FREEBSD:56BA4513-A1BE-11EB-9072-D4C9EF517024
- GLSA-202012-11
- GLSA-202101-07
- MS:CVE-2020-8277
- openSUSE-SU-2020:2045-1
- openSUSE-SU-2020:2092-1
- openSUSE-SU-2021:0064-1
- openSUSE-SU-2021:0066-1
- RHSA-2020:5499
- RHSA-2021:0551
- RLSA-2020:5499
- RLSA-2021:0551
- SUSE-SU-2020:3478-1
- SUSE-SU-2020:3549-1
- SUSE-SU-2021:0061-1
- SUSE-SU-2021:0062-1
- USN-4638-1
Source | # ID | Name | URL |
---|---|---|---|
FreeBSD VuXML | https://nodejs.org/en/blog/vulnerability/november-2020-security-releases/ |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |