漏洞信息详情
Oracle GraalVM 资源管理错误漏洞
漏洞简介
Oracle GraalVM是美国甲骨文(Oracle)公司的一套使用Java语言编写的即时编译器。该产品支持多种编程语言和执行模式。
Oracle GraalVM 的 Oracle GraalVM Enterprise Edition 存在资源管理错误漏洞,该漏洞源于网络系统或产品对系统资源(如内存、磁盘空间、文件等)的管理不当。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://nodejs.org/en/blog/vulnerability/november-2020-security-releases/
参考网址
来源:MISC
链接:https://hackerone.com/reports/1033107
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/A7WH7W46OZSEUHWBHD7TCH3LRFY52V6Z/
来源:GENTOO
链接:https://security.gentoo.org/glsa/202012-11
来源:N/A
链接:https://www.oracle.com//security-alerts/cpujul2021.html
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/BEJBY3RJB3XWUOJFGZM5E3EMQ7MFM3UT/
来源:MISC
链接:https://www.oracle.com/security-alerts/cpujan2021.html
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/VXLJY4764LYVJPC7NCDLE2UMQ3QC5OI2/
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/EEIV4CH6KNVZK63Y6EKVN2XDW7IHSJBJ/
来源:MISC
链接:https://www.oracle.com/security-alerts/cpuoct2021.html
来源:GENTOO
链接:https://security.gentoo.org/glsa/202101-07
来源:CONFIRM
链接:https://nodejs.org/en/blog/vulnerability/november-2020-security-releases/
来源:MISC
链接:https://www.oracle.com/security-alerts/cpuApr2021.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/160528/Red-Hat-Security-Advisory-2020-5499-01.html
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-api-connect-is-vulnerable-to-denial-of-service-dos-via-node-js-cve-2020-8277/
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021072780
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2020-8277
来源:www.oracle.com
链接:https://www.oracle.com/security-alerts/cpuapr2021.html
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-cloud-pak-for-security-contains-security-vulnerabilities/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.4214/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-node-js-affect-ibm-infosphere-information-server/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-a-security-vulnerability-in-node-js-affects-ibm-cloud-automation-manager/
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/160702/Gentoo-Linux-Security-Advisory-202012-11.html
来源:www.ibm.com
链接:https://www.ibm.com/support/pages/node/6497219
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.4264/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-cloud-transformation-advisor-is-affected-by-a-node-js-vulnerability/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-cloud-pak-for-integration-is-vulnerable-to-node-js-cve-2020-8277/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3353
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/161287/Red-Hat-Security-Advisory-2021-0421-01.html
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021092209
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021042110
来源:www.oracle.com
链接:https://www.oracle.com/security-alerts/cpujul2021.html
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-affect-ibm-sdk-for-node-js-in-ibm-cloud-4/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-a-security-vulnerability-in-node-js-affects-ibm-cloud-pak-for-multicloud-management/
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/160294/Red-Hat-Security-Advisory-2020-5305-01.html
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/Node-Core-denial-of-service-via-Numerous-DNS-Responses-33903
来源:www.oracle.com
链接:https://www.oracle.com/security-alerts/cpujan2021.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/160892/Gentoo-Linux-Security-Advisory-202101-07.html
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-watson-openscale-on-cloud-pak-for-data-is-impacted-by-cve-2020-8277/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-potential-vulnerability-with-node-js-6/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-watson-discovery-for-ibm-cloud-pak-for-data-affected-by-vulnerability-in-node-js-2/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.0587
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.4356/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.4441/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.4188/
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/160141/Ubuntu-Security-Notice-USN-4638-1.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.4164/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-affect-ibm-cloud-pak-for-automation/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-version-12-18-4-of-node-js-included-in-ibm-netcool-operations-insight-1-6-2-x-has-a-security-vulnerability/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-affect-ibm-rational-application-developer-for-websphere-software/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.0695
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.0112/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-streams-flows-might-be-affected-by-some-underlying-node-js-vulnerabilities/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-app-connect-enterprise-certified-container-may-be-vulnerable-to-a-denial-of-service-attack-through-a-dns-lookup-that-returns-a-large-number-of-responses-cve-2020-8277/
受影响实体
暂无
补丁
- node core 资源管理错误漏洞的修复措施<!--2020-11-16-->
还没有评论,来说两句吧...