ZeroHour

CVE-2019-15604

PoC
CVSS 3.1
7.5 high
EPSS
20%p97
Published
()
Modified
Description

Improper Certificate Validation in Node.js 10, 12, and 13 causes the process to abort when sending a crafted X.509 certificate

Vendors
nodejsdebianopensuseredhatoracle
Products
node.js, debian linux, leap, software collections, enterprise linux, enterprise linux eus, enterprise linux server aus, enterprise linux server tus, communications cloud native core network function cloud native environment, graalvm
Weakness
CWE-295
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.