Skip to content

Commit

Permalink
blog: credit reporters (#3206)
Browse files Browse the repository at this point in the history
  • Loading branch information
sam-github committed Jun 3, 2020
1 parent 024ad6e commit a41c3dc
Showing 1 changed file with 2 additions and 0 deletions.
2 changes: 2 additions & 0 deletions locale/en/blog/vulnerability/june-2020-security-releases.md
Original file line number Diff line number Diff line change
Expand Up @@ -26,6 +26,8 @@ Receiving unreasonably large HTTP/2 SETTINGS frames can consume 100% CPU to proc

The HTTP/2 session frame is limited to 32 settings by default. This can be configured if necessary using the `maxSettings` option.

Thank you to Jordan Zebor and Adam Cabrey of F5 Networks for reporting this.

Affects Node.js 10.x, 12.x, and 14.x.

### `napi_get_value_string_*()` allows various kinds of memory corruption (High) (CVE-2020-8174)
Expand Down

0 comments on commit a41c3dc

Please sign in to comment.