Node. js is facing two important security vulnerabilities and is planned to be repaired next week.
The Node. js Foundation discloses a denial of service and an out-of-bounds Access Vulnerability, and plans to provide patch updates next week to fix these two critical vulnerabilities.
The Node. js Foundation announced today that the most popular server-side JavaScript platform includes "a high-intensity Denial Of Service Vulnerability" and "a low-intensity V8 Access Vulnerability ". V8 is a JavaScript engine developed by Google. Node. js officially marked DoS Vulnerabilities as CVE (Common Vulnerabilities and Exposures) 2015-8027, access Vulnerabilities as CVE-2015-6764.
"We have two unclosed security vulnerabilities that we plan to fix on Wednesday, December 2. "Mikeal Rogers, managing Node. js Foundation, revealed. Vulnerabilities are provided in nodejs.org through patches, and these vulnerabilities are not yet exploited.
In this announcement, DoS Vulnerabilities are widely found in Node. js and v0.12.x-v5.x. External access vulnerabilities have minor impacts, mainly in v4.x-v5.x.
Although these two vulnerabilities are very serious. the js Foundation has always stressed that Node. js users don't have to worry about it. These vulnerabilities have little impact on the community, and these two vulnerabilities are also Node. node. the js Foundation will take it seriously and upgrade it soon.
Rogers also said that since the foundation Node. js joins the Linux Foundation, the security of Node. js has improved a lot and more general security policies are available.
You may also like the following content about Node. js:
Install and configure Node. js v4.0.0 on Ubuntu 14.04/15.04
How to install Node. js in CentOS 7
Build a Node. js development environment in Ubuntu 14.04
Install and configure the Node. js development environment in javasru 12.04
Getting started with Node. Js [PDF + related Code]
Node. js Development Guide hd pdf Chinese version + source code
Node. js getting started Development Guide
Compile and install Node. js in Ubuntu
Node. js details: click here
Node. js: click here
This article permanently updates the link address: