First published: Mon Oct 21 2013(Updated: )
The HTTP server in Node.js 0.10.x before 0.10.21 and 0.8.x before 0.8.26 allows remote attackers to cause a denial of service (memory and CPU consumption) by sending a large number of pipelined requests without reading the response.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Node.js | =0.8.0 | |
Node.js | =0.8.1 | |
Node.js | =0.8.2 | |
Node.js | =0.8.3 | |
Node.js | =0.8.4 | |
Node.js | =0.8.5 | |
Node.js | =0.8.6 | |
Node.js | =0.8.7 | |
Node.js | =0.8.8 | |
Node.js | =0.8.9 | |
Node.js | =0.8.10 | |
Node.js | =0.8.11 | |
Node.js | =0.8.12 | |
Node.js | =0.8.13 | |
Node.js | =0.8.14 | |
Node.js | =0.8.15 | |
Node.js | =0.8.16 | |
Node.js | =0.8.17 | |
Node.js | =0.8.18 | |
Node.js | =0.8.19 | |
Node.js | =0.8.20 | |
Node.js | =0.8.21 | |
Node.js | =0.8.22 | |
Node.js | =0.8.23 | |
Node.js | =0.8.24 | |
Node.js | =0.8.25 | |
Node.js | =0.10.0 | |
Node.js | =0.10.1 | |
Node.js | =0.10.2 | |
Node.js | =0.10.3 | |
Node.js | =0.10.4 | |
Node.js | =0.10.5 | |
Node.js | =0.10.6 | |
Node.js | =0.10.7 | |
Node.js | =0.10.8 | |
Node.js | =0.10.9 | |
Node.js | =0.10.10 | |
Node.js | =0.10.11 | |
Node.js | =0.10.12 | |
Node.js | =0.10.13 | |
Node.js | =0.10.14 | |
Node.js | =0.10.15 | |
Node.js | =0.10.16 | |
Node.js | =0.10.17 | |
Node.js | =0.10.18 | |
Node.js | =0.10.19 | |
Node.js | =0.10.20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4450 is considered a moderate severity vulnerability as it allows denial of service through resource consumption.
To fix CVE-2013-4450, upgrade Node.js to version 0.10.21 or later for the 0.10.x branch and 0.8.26 or later for the 0.8.x branch.
CVE-2013-4450 affects Node.js versions 0.10.x before 0.10.21 and 0.8.x before 0.8.26.
CVE-2013-4450 enables remote attackers to conduct denial of service attacks by sending many pipelined requests.
Yes, if your Node.js application is using any affected version below 0.8.26 or 0.10.21, it is vulnerable to CVE-2013-4450.