QID 375997
Date Published: 2021-11-01
QID 375997: Node.js Modern-Async Module Denial of Service (DoS) Vulnerability
Node.js is an open-source, cross-platform, back-end JavaScript runtime environment that runs on the V8 engine and executes JavaScript code outside a web browser.
CVE-2021-41167: modern-async is an open source JavaScript tooling library for asynchronous operations using async/await and promises
Affected Versions:
Modern-Async prior to 1.0.4
QID Detection Logic:(Authenticated)
This QID checks for server banner to detect the vulnerable version of Modern-Async package using "npm list | grep 'modern-async'"
A remote attacker could exploit this vulnerability to cause a denial of service condition.
Vendor References
CVEs related to QID 375997
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2021-41167 |
|