CVE Published: 13/06/2018 |
CVE Updated: 16/09/2024 |
CVE Year: 2018 Source: nodejs |
Vendor: The Node.js Project |
Product: Node.js Status : PUBLISHED
CVE-2018-7162 Description
All versions of Node.js 9.x and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of service (DoS) by causing a node process which provides an http server supporting TLS server to crash. This can be accomplished by sending duplicate/unexpected messages during the handshake. This vulnerability has been addressed by updating the TLS implementation.