// For flags

CVE-2017-11499

nodejs: Constant Hashtable Seeds vulnerability

Severity Score

7.5
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Node.js v4.0 through v4.8.3, all versions of v5.x, v6.0 through v6.11.0, v7.0 through v7.10.0, and v8.0 through v8.1.3 was susceptible to hash flooding remote DoS attacks as the HashTable seed was constant across a given released version of Node.js. This was a result of building with V8 snapshots enabled by default which caused the initially randomized seed to be overwritten on startup.

Node.js versión v4.0 hasta v4.8.3, todas las versiones de v5.x, versión v6.0 hasta v6.11.0, versión v7.0 hasta v7.10.0, y versión v8.0 hasta v8.1.3, fue susceptible a ataques DoS remotos de inundación de hash ya que el seed HashTable fue constante en una versión dada de Node.js. Esto fue el resultado de la compilación con instantáneas V8 habilitadas por defecto, lo que causó que el seed aleatorizado inicialmente se sobrescribiera en el arranque.

It was found that Node.js was using a non-randomized seed when populating hash tables. An attacker, able to supply a large number of inputs, could send specially crafted entries to the Node.js application, maximizing hash collisions to trigger an excessive amount of CPU usage, resulting in a denial of service.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2017-07-20 CVE Reserved
  • 2017-07-25 CVE Published
  • 2023-05-10 EPSS Updated
  • 2024-08-05 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-20: Improper Input Validation
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
4.0.0
Search vendor "Nodejs" for product "Node.js" and version "4.0.0"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
4.1.0
Search vendor "Nodejs" for product "Node.js" and version "4.1.0"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
4.1.1
Search vendor "Nodejs" for product "Node.js" and version "4.1.1"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
4.1.2
Search vendor "Nodejs" for product "Node.js" and version "4.1.2"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
4.2.0
Search vendor "Nodejs" for product "Node.js" and version "4.2.0"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
4.2.1
Search vendor "Nodejs" for product "Node.js" and version "4.2.1"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
4.2.2
Search vendor "Nodejs" for product "Node.js" and version "4.2.2"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
4.2.3
Search vendor "Nodejs" for product "Node.js" and version "4.2.3"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
4.2.4
Search vendor "Nodejs" for product "Node.js" and version "4.2.4"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
4.2.5
Search vendor "Nodejs" for product "Node.js" and version "4.2.5"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
4.2.6
Search vendor "Nodejs" for product "Node.js" and version "4.2.6"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
4.3.0
Search vendor "Nodejs" for product "Node.js" and version "4.3.0"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
4.3.1
Search vendor "Nodejs" for product "Node.js" and version "4.3.1"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
4.3.2
Search vendor "Nodejs" for product "Node.js" and version "4.3.2"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
4.4.0
Search vendor "Nodejs" for product "Node.js" and version "4.4.0"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
4.4.1
Search vendor "Nodejs" for product "Node.js" and version "4.4.1"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
4.4.2
Search vendor "Nodejs" for product "Node.js" and version "4.4.2"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
4.4.3
Search vendor "Nodejs" for product "Node.js" and version "4.4.3"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
4.4.4
Search vendor "Nodejs" for product "Node.js" and version "4.4.4"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
4.4.5
Search vendor "Nodejs" for product "Node.js" and version "4.4.5"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
4.4.6
Search vendor "Nodejs" for product "Node.js" and version "4.4.6"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
4.4.7
Search vendor "Nodejs" for product "Node.js" and version "4.4.7"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
4.5.0
Search vendor "Nodejs" for product "Node.js" and version "4.5.0"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
4.6.0
Search vendor "Nodejs" for product "Node.js" and version "4.6.0"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
4.6.1
Search vendor "Nodejs" for product "Node.js" and version "4.6.1"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
4.6.2
Search vendor "Nodejs" for product "Node.js" and version "4.6.2"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
4.7.0
Search vendor "Nodejs" for product "Node.js" and version "4.7.0"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
4.7.1
Search vendor "Nodejs" for product "Node.js" and version "4.7.1"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
4.7.2
Search vendor "Nodejs" for product "Node.js" and version "4.7.2"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
4.7.3
Search vendor "Nodejs" for product "Node.js" and version "4.7.3"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
4.8.0
Search vendor "Nodejs" for product "Node.js" and version "4.8.0"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
4.8.1
Search vendor "Nodejs" for product "Node.js" and version "4.8.1"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
4.8.2
Search vendor "Nodejs" for product "Node.js" and version "4.8.2"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
4.8.3
Search vendor "Nodejs" for product "Node.js" and version "4.8.3"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
5.0.0
Search vendor "Nodejs" for product "Node.js" and version "5.0.0"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
5.1.0
Search vendor "Nodejs" for product "Node.js" and version "5.1.0"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
5.1.1
Search vendor "Nodejs" for product "Node.js" and version "5.1.1"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
5.2.0
Search vendor "Nodejs" for product "Node.js" and version "5.2.0"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
5.3.0
Search vendor "Nodejs" for product "Node.js" and version "5.3.0"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
5.4.0
Search vendor "Nodejs" for product "Node.js" and version "5.4.0"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
5.4.1
Search vendor "Nodejs" for product "Node.js" and version "5.4.1"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
5.5.0
Search vendor "Nodejs" for product "Node.js" and version "5.5.0"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
5.6.0
Search vendor "Nodejs" for product "Node.js" and version "5.6.0"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
5.7.0
Search vendor "Nodejs" for product "Node.js" and version "5.7.0"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
5.7.1
Search vendor "Nodejs" for product "Node.js" and version "5.7.1"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
5.8.0
Search vendor "Nodejs" for product "Node.js" and version "5.8.0"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
5.9.0
Search vendor "Nodejs" for product "Node.js" and version "5.9.0"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
5.9.1
Search vendor "Nodejs" for product "Node.js" and version "5.9.1"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
5.10.0
Search vendor "Nodejs" for product "Node.js" and version "5.10.0"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
5.10.1
Search vendor "Nodejs" for product "Node.js" and version "5.10.1"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
5.11.0
Search vendor "Nodejs" for product "Node.js" and version "5.11.0"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
5.11.1
Search vendor "Nodejs" for product "Node.js" and version "5.11.1"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
5.12.0
Search vendor "Nodejs" for product "Node.js" and version "5.12.0"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
6.0.0
Search vendor "Nodejs" for product "Node.js" and version "6.0.0"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
6.1.0
Search vendor "Nodejs" for product "Node.js" and version "6.1.0"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
6.2.0
Search vendor "Nodejs" for product "Node.js" and version "6.2.0"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
6.2.1
Search vendor "Nodejs" for product "Node.js" and version "6.2.1"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
6.2.2
Search vendor "Nodejs" for product "Node.js" and version "6.2.2"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
6.3.0
Search vendor "Nodejs" for product "Node.js" and version "6.3.0"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
6.3.1
Search vendor "Nodejs" for product "Node.js" and version "6.3.1"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
6.4.0
Search vendor "Nodejs" for product "Node.js" and version "6.4.0"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
6.5.0
Search vendor "Nodejs" for product "Node.js" and version "6.5.0"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
6.6.0
Search vendor "Nodejs" for product "Node.js" and version "6.6.0"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
6.7.0
Search vendor "Nodejs" for product "Node.js" and version "6.7.0"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
6.8.0
Search vendor "Nodejs" for product "Node.js" and version "6.8.0"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
6.8.1
Search vendor "Nodejs" for product "Node.js" and version "6.8.1"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
6.9.0
Search vendor "Nodejs" for product "Node.js" and version "6.9.0"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
6.9.1
Search vendor "Nodejs" for product "Node.js" and version "6.9.1"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
6.9.2
Search vendor "Nodejs" for product "Node.js" and version "6.9.2"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
6.9.3
Search vendor "Nodejs" for product "Node.js" and version "6.9.3"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
6.9.4
Search vendor "Nodejs" for product "Node.js" and version "6.9.4"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
6.9.5
Search vendor "Nodejs" for product "Node.js" and version "6.9.5"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
6.10.0
Search vendor "Nodejs" for product "Node.js" and version "6.10.0"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
6.10.1
Search vendor "Nodejs" for product "Node.js" and version "6.10.1"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
6.10.2
Search vendor "Nodejs" for product "Node.js" and version "6.10.2"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
6.10.3
Search vendor "Nodejs" for product "Node.js" and version "6.10.3"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
6.11.0
Search vendor "Nodejs" for product "Node.js" and version "6.11.0"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
6.11.1
Search vendor "Nodejs" for product "Node.js" and version "6.11.1"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
7.0.0
Search vendor "Nodejs" for product "Node.js" and version "7.0.0"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
7.1.0
Search vendor "Nodejs" for product "Node.js" and version "7.1.0"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
7.2.0
Search vendor "Nodejs" for product "Node.js" and version "7.2.0"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
7.2.1
Search vendor "Nodejs" for product "Node.js" and version "7.2.1"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
7.3.0
Search vendor "Nodejs" for product "Node.js" and version "7.3.0"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
7.4.0
Search vendor "Nodejs" for product "Node.js" and version "7.4.0"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
7.5.0
Search vendor "Nodejs" for product "Node.js" and version "7.5.0"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
7.6.0
Search vendor "Nodejs" for product "Node.js" and version "7.6.0"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
7.7.0
Search vendor "Nodejs" for product "Node.js" and version "7.7.0"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
7.7.1
Search vendor "Nodejs" for product "Node.js" and version "7.7.1"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
7.7.2
Search vendor "Nodejs" for product "Node.js" and version "7.7.2"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
7.7.3
Search vendor "Nodejs" for product "Node.js" and version "7.7.3"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
7.7.4
Search vendor "Nodejs" for product "Node.js" and version "7.7.4"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
7.8.0
Search vendor "Nodejs" for product "Node.js" and version "7.8.0"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
7.9.0
Search vendor "Nodejs" for product "Node.js" and version "7.9.0"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
7.10.0
Search vendor "Nodejs" for product "Node.js" and version "7.10.0"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
7.10.1
Search vendor "Nodejs" for product "Node.js" and version "7.10.1"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
8.0.0
Search vendor "Nodejs" for product "Node.js" and version "8.0.0"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
8.1.0
Search vendor "Nodejs" for product "Node.js" and version "8.1.0"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
8.1.1
Search vendor "Nodejs" for product "Node.js" and version "8.1.1"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
8.1.2
Search vendor "Nodejs" for product "Node.js" and version "8.1.2"
-
Affected
Nodejs
Search vendor "Nodejs"
Node.js
Search vendor "Nodejs" for product "Node.js"
8.1.3
Search vendor "Nodejs" for product "Node.js" and version "8.1.3"
-
Affected