MEDIUM 6.5 Microsoft
CVE-2024-22025
A vulnerability in Node.js has been identified allowing for a Denial of Service (DoS) attack through resource exhaustion when using the fetch() function to retrieve content from an untrusted URL. The vulnerability stems from the fact that the fetch() function in Node.js always decodes Brotli making it possible for an attacker to cause resource exhaustion when fetching content from an untrusted URL. An attacker controlling the URL passed into fetch() can exploit this vulnerability to exhaust memory potentially leading to process termination depending on the system configuration.
Microsoft Security Update 2024-Mar: A vulnerability in Node.js has been identified allowing for a Denial of Service (DoS) attack through resource exhaustion when using the fetch() function to retrieve content from an untrusted URL.
The vulnerability stems from the fact that the fetch() function in Node.js always decodes Brotli making it possible for an attacker to cause resource exhaustion when fetching content from an untrusted URL.
An attacker controlling the URL passed into fetch() can exploit this vulnerability to exhaust memory potentially leading to process termination depending on the system configuration.
Affected Products
- cbl2 nodejs18 18.18.2-5 on CBL Mariner 2.0
- cbl2 nodejs 16.20.2-4 on CBL Mariner 2.0
- azl3 nodejs 20.14.0-1 on Azure Linux 3.0
- azl3 nodejs 20.10.0-2 on Azure Linux 3.0
- cbl2 nodejs18 18.18.2-7 on CBL Mariner 2.0
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-22025
- https://nvd.nist.gov/vuln/detail/CVE-2024-22025
This medium severity vulnerability with a CVSS score of 6.5 was published on 2024-03-12 via Microsoft. Affected: cbl2 nodejs18 18.18.2-5 on CBL Mariner 2.0, cbl2 nodejs 16.20.2-4 on CBL Mariner 2.0, azl3 nodejs 20.14.0-1 on Azure Linux 3.0 and 2 more.
vulnfeed aggregates 10103 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.