High severity7.5NVD Advisory· Published Nov 19, 2020· Updated Jun 17, 2026
CVE-2020-8277
CVE-2020-8277
Description
A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versions < 15.2.1, < 14.15.1, and < 12.19.1 by getting the application to resolve a DNS record with a larger number of responses. This is fixed in 15.2.1, 14.15.1, and 12.19.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
37- cpe:2.3:a:oracle:blockchain_platform:*:*:*:*:*:*:*:*Range: <21.1.2
cpe:2.3:a:oracle:graalvm:19.3.4:*:*:*:enterprise:*:*:*+ 1 more
- cpe:2.3:a:oracle:graalvm:19.3.4:*:*:*:enterprise:*:*:*
- cpe:2.3:a:oracle:graalvm:20.3.0:*:*:*:enterprise:*:*:*
- cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:*:*:*:*:*:*:*:*Range: <9.2.6.0
cpe:2.3:a:oracle:retail_xstore_point_of_service:16.0.6:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:oracle:retail_xstore_point_of_service:16.0.6:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:retail_xstore_point_of_service:17.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:retail_xstore_point_of_service:18.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:retail_xstore_point_of_service:19.0.2:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
- osv-coords21 versionspkg:bitnami/nodepkg:bitnami/node-minpkg:rpm/almalinux/nodejs-nodemonpkg:rpm/almalinux/nodejs-packagingpkg:rpm/opensuse/c-ares&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/c-ares&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/c-ares&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/c-ares-tests&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/c-ares-tests&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/nodejs12&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/nodejs14&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/nodejs14&distro=openSUSE%20Tumbleweedpkg:rpm/suse/c-ares&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/c-ares&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/c-ares&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP1pkg:rpm/suse/c-ares&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP2pkg:rpm/suse/c-ares&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/c-ares&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/nodejs12&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2012pkg:rpm/suse/nodejs12&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2015%20SP2pkg:rpm/suse/nodejs14&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2015%20SP2
>= 12.16.3, < 12.19.1+ 20 more
- (no CPE)range: >= 12.16.3, < 12.19.1
- (no CPE)range: >= 12.16.3, < 12.19.1
- (no CPE)range: < 1.18.3-1.module_el8.3.0+2023+d2377ea3
- (no CPE)range: < 17-3.module_el8.4.0+2224+b07ac28e
- (no CPE)range: < 1.17.0-lp151.3.6.1
- (no CPE)range: < 1.17.0-lp152.2.3.1
- (no CPE)range: < 1.17.2-2.2
- (no CPE)range: < 1.17.0-lp151.3.6.1
- (no CPE)range: < 1.17.0-lp152.2.3.1
- (no CPE)range: < 12.20.1-lp152.3.9.1
- (no CPE)range: < 14.15.4-lp152.5.1
- (no CPE)range: < 14.17.5-1.2
- (no CPE)range: < 1.17.0-3.8.1
- (no CPE)range: < 1.17.0-3.8.1
- (no CPE)range: < 1.17.0-3.8.1
- (no CPE)range: < 1.17.0-3.8.1
- (no CPE)range: < 1.17.0-3.8.1
- (no CPE)range: < 1.17.0-3.8.1
- (no CPE)range: < 12.19.1-1.23.1
- (no CPE)range: < 12.20.1-4.10.1
- (no CPE)range: < 14.15.4-5.6.1
Patches
Vulnerability mechanics
References
13- nodejs.org/en/blog/vulnerability/november-2020-security-releases/nvdPatchVendor Advisory
- www.oracle.com//security-alerts/cpujul2021.htmlnvdPatchThird Party Advisory
- www.oracle.com/security-alerts/cpuApr2021.htmlnvdPatchThird Party Advisory
- www.oracle.com/security-alerts/cpuapr2022.htmlnvdPatchThird Party Advisory
- www.oracle.com/security-alerts/cpujan2021.htmlnvdPatchThird Party Advisory
- www.oracle.com/security-alerts/cpuoct2021.htmlnvdPatchThird Party Advisory
- hackerone.com/reports/1033107nvdPermissions RequiredThird Party Advisory
- security.gentoo.org/glsa/202012-11nvdThird Party Advisory
- security.gentoo.org/glsa/202101-07nvdThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A7WH7W46OZSEUHWBHD7TCH3LRFY52V6Z/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BEJBY3RJB3XWUOJFGZM5E3EMQ7MFM3UT/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EEIV4CH6KNVZK63Y6EKVN2XDW7IHSJBJ/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VXLJY4764LYVJPC7NCDLE2UMQ3QC5OI2/nvd
News mentions
0No linked articles in our index yet.