[FREEBSD:AD792169-2AA4-11EB-AB71-0022489AD614] Node.js -- November 2020 Security Releases

Severity High
Affected Packages 3
CVEs 1

Node.js reports:

  Updates are now available for v12.x, v14.x and v15.x Node.js release lines for the following issues.
  Denial of Service through DNS request (CVE-2020-8277)
  A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of service by getting the application to resolve a DNS record with a larger number of responses.
Package Affected Version
pkg:freebsd/node14 < 14.15.1
pkg:freebsd/node12 < 12.19.1
pkg:freebsd/node < 15.2.1
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:freebsd/node14 node14 < 14.15.1
Affected pkg:freebsd/node12 node12 < 12.19.1
Affected pkg:freebsd/node node < 15.2.1
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...