CVE-2013-4450
EPSS 68.7%
Description
The HTTP server in Node.js 0.10.x before 0.10.21 and 0.8.x before 0.8.26 allows remote attackers to cause a denial of service (memory and CPU consumption) by sending a large number of pipelined requests without reading the response.
How to fix CVE-2013-4450
To remediate CVE-2013-4450, upgrade the affected package to a fixed version below.
- Debian/nodejs—upgrade to 0.10.21~dfsg1-1 or later
Is CVE-2013-4450 being exploited?
Likely — EPSS is 68.7%, placing CVE-2013-4450 in the top tier of vulnerabilities by exploitation probability. Prioritise patching.
Affected packages (1)
- from 0, < 0.10.21~dfsg1-1