CVE-2014-3742
File Descriptor Leak Can Cause DoS Vulnerability in hapi
EPSS 2.4%
描述
Versions 2.0.x and 2.1.x of hapi are vulnerable to a denial of service attack via a file descriptor leak. When triggered repeatedly, this leak will cause the server to run out of file descriptors and the node process to die. The effort required to take down a server depends on the process file descriptor limit. No other side effects or exploits have been identified. ## Recommendation - Please upgrade to version 2.2.x or above as soon as possible.
如何修補 CVE-2014-3742
要修補 CVE-2014-3742,請將受影響套件升級到下列已修補版本。
- npm/hapi—升級至 2.2.0 或更新版本
CVE-2014-3742 正在被利用嗎?
低 — EPSS 為 2.4%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- >= 2.0.0, < 2.2.0