CVE-2019-5737 -- nodejsDeprecated |
ID: oval:org.secpod.oval:def:1902147 | Date: (C)2019-07-12 (M)2024-04-17 |
Class: VULNERABILITY | Family: unix |
An attacker can cause a Denial of Service by establishing an HTTP or HTTPS connection in keep-alive mode and by sending headers very slowly thereby keeping the connection and associated resources alive for a long period of time. Attack potential is mitigated by the use of a load balancer or other proxy layer. This vulnerability is an extension of CVE-2018-12121, addressed in November and impacts all active Node.js release lines including 6.x before 6.17.0, 8.x before 8.15.1, 10.x before 10.15.2, and 11.x before 11.10.1.
Platform: |
Ubuntu 18.10 |
Ubuntu 18.04 |