VulnerabilityModified
CVE-2022-36127
A vulnerability in Apache SkyWalking NodeJS Agent prior to 0.5.1.
HIGH 7.5EPSS 1.81%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.81%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A vulnerability in Apache SkyWalking NodeJS Agent prior to 0.5.1. The vulnerability will cause NodeJS services that has this agent installed to be unavailable if the OAP is unhealthy and NodeJS agent can't establish the connection.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 1.81% probability · 77th percentile
- CISA KEV
- Not listed
- Affected
- apache/skywalking nodejs agent
- Source
- security@apache.org
References
- http://www.openwall.com/lists/oss-security/2022/07/18/1Mailing List, Third Party Advisory
- https://lists.apache.org/thread/x238wo4r5goy39dxdjcmlofp6gcdnqr3Mailing List, Release Notes, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2022/07/18/1Mailing List, Third Party Advisory
- https://lists.apache.org/thread/x238wo4r5goy39dxdjcmlofp6gcdnqr3Mailing List, Release Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.