漏洞信息详情
Node.js 资源管理错误漏洞
漏洞简介
Joyent Node.js是美国Joyent公司的一套建立在Google V8 JavaScript引擎之上的网络应用平台。该平台主要用于构建高度可伸缩的应用程序,以及编写能够处理数万条且同时连接到一个物理机的连接代码。
Node.js存在资源管理错误漏洞。该漏洞源于Node.js容易受到释放后重用攻击。利用该漏攻击者可构造内存溢出,从而导致进程行为的改变。该漏洞最大威胁是影响系统的机密性和完整性。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://access.redhat.com/security/cve/cve-2021-22930
参考网址
来源:MISC
链接:https://nodejs.org/en/blog/vulnerability/july-2021-security-releases-2/
来源:CONFIRM
链接:https://security.netapp.com/advisory/ntap-20211112-0002/
来源:MISC
链接:https://hackerone.com/reports/1238162
来源:www.ibm.com
链接:https://www.ibm.com/support/pages/node/6489845
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2907
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2021-22930
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021080324
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2834
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3219
来源:www.ibm.com
链接:https://www.ibm.com/support/pages/node/6493269
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/164299/Red-Hat-Security-Advisory-2021-3666-01.html
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/Node-Core-use-after-free-via-Stream-Canceling-Close-Http2-36018
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2858
来源:www.ibm.com
链接:https://www.ibm.com/support/pages/node/6514837
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3331
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3231
来源:www.ibm.com
链接:https://www.ibm.com/support/pages/node/6507029
来源:www.ibm.com
链接:https://www.ibm.com/support/pages/node/6509604
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2950
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/163937/Red-Hat-Security-Advisory-2021-3280-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2993
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3169
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/164257/Red-Hat-Security-Advisory-2021-3638-01.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/164229/Red-Hat-Security-Advisory-2021-3623-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3196
来源:access.redhat.com
链接:https://access.redhat.com/security/cve/cve-2021-22930
来源:www.ibm.com
链接:https://www.ibm.com/support/pages/node/6498023
受影响实体
暂无
补丁
- Node.js 资源管理错误漏洞的修复措施<!--2021-7-29-->
还没有评论,来说两句吧...