VDB
BDU%3A2024-06239
BDU%3A2024-06239
PUBLISHED
CVSS 7.800000190734863 HIGH
Уязвимость конфигурации server.maxHeadersCount() клиент-серверной библиотеки ws программной платформы Node.js, позволяющая нарушителю вызвать отказ в обслуживании
Risk Scores
CVSS 2.0
7.800000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| ООО «Ред Софт», OpenJS Foundation, АО «СберТех» | РЕД ОС (запись в едином реестре российских программ №3751), ws, Platform V SberLinux OS Server (запись в едином реестре российских программ №18785) |
Timeline
- Aug 14, 2024 CVE Published
- Sep 12, 2025 CVE Updated
References
- https://github.com/websockets/ws/commit/22c28763234aa75a7e1b76f5c01c181260d7917f url
- https://github.com/websockets/ws/commit/4abd8f6de4b0b65ef80b3ff081989479ed93377e url
- https://github.com/websockets/ws/commit/e55e5106f10fcbaac37cfa89759e4cc0d073a52c url
- https://github.com/websockets/ws/commit/eeb76d313e2a00dd5247ca3597bba7877d064a63 url
- https://github.com/websockets/ws/issues/2230 url
- https://github.com/websockets/ws/pull/2231 url
- https://github.com/websockets/ws/security/advisories/GHSA-3h5v-q93c-6h6q url
- https://nodejs.org/api/http.html#servermaxheaderscount url
- https://vuldb.com/ru/?id.268837 url
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ url