Get a Pentest and security assessment of your IT network.

Cyber Security

Node.js fixes severe HTTP bug that could let attackers crash apps

Node.js has released updates for a high severity vulnerability that could be exploited by attackers. The use-after-free vulnerability, tracked as CVE-2021-22930, is to do with how HTTP2 streams are handled in the language. This can lead to unexpected behaviors such as application crashes, or even remote code execution (RCE) in some cases. The fixes landed in the latest release 16.6.0 and were also backported to versions 12.22.4 (LTS) and 14.17.4.

Source: https://www.bleepingcomputer.com/news/security/nodejs-fixes-severe-http-bug-that-could-let-attackers-crash-apps/

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security