ืคื’ื™ืขื•ืช ื‘ืžื•ื“ื•ืœ http2 ืž-Node.js

ื”ืžืคืชื—ื™ื ืฉืœ ืคืœื˜ืคื•ืจืžืช ื”-JavaScript ื‘ืฆื“ ื”ืฉืจืช Node.js ืคืจืกืžื• ืžื”ื“ื•ืจื•ืช ืžืชืงื ื•ืช 12.22.4, 14.17.4 ื•-16.6.0, ื”ืžืชืงื ื™ื ื—ืœืงื™ืช ืคื’ื™ืขื•ืช (CVE-2021-22930) ื‘ืžื•ื“ื•ืœ http2 (ืœืงื•ื— HTTP/2.0) , ื”ืžืืคืฉืจ ืœืš ืœื™ื–ื•ื ืงืจื™ืกืช ืชื”ืœื™ืš ืื• ืื•ืœื™ ืœืืจื’ืŸ ืืช ื‘ื™ืฆื•ืข ื”ืงื•ื“ ืฉืœืš ื‘ืžืขืจื›ืช ื‘ืขืช ื’ื™ืฉื” ืœืžืืจื— ื”ื ืฉืœื˜ ืขืœ ื™ื“ื™ ื”ืชื•ืงืฃ.

ื”ื‘ืขื™ื” ื ื’ืจืžืช ืขืœ ื™ื“ื™ ื’ื™ืฉื” ืœื–ื™ื›ืจื•ืŸ ืฉื›ื‘ืจ ืคื ื•ื™ ื‘ืขืช ืกื’ื™ืจืช ื—ื™ื‘ื•ืจ ืœืื—ืจ ืงื‘ืœืช ืžืกื’ืจื•ืช RST_STREAM (ืื™ืคื•ืก ืฉืจืฉื•ืจ) ืขื‘ื•ืจ ืฉืจืฉื•ืจื™ื ืฉืžื‘ืฆืขื™ื ืคืขื•ืœื•ืช ืงืจื™ืื” ืื™ื ื˜ื ืกื™ื‘ื™ื•ืช ื”ื—ื•ืกืžื•ืช ื›ืชื™ื‘ื”. ืื ืžืกื’ืจืช RST_STREAM ืžืชืงื‘ืœืช ืœืœื ืฆื™ื•ืŸ ืงื•ื“ ืฉื’ื™ืื”, ืžื•ื“ื•ืœ http2 ืงื•ืจื ื‘ื ื•ืกืฃ ืœื”ืœื™ืš ื ื™ืงื•ื™ ืขื‘ื•ืจ ื ืชื•ื ื™ื ืฉื›ื‘ืจ ื”ืชืงื‘ืœื•, ืžืžื ื• ื ืงืจื ืฉื•ื‘ ืžื˜ืคืœ ื”ืกื’ื™ืจื” ืขื‘ื•ืจ ื”ื–ืจื ืฉื›ื‘ืจ ืกื’ื•ืจ, ืžื” ืฉืžื•ื‘ื™ืœ ืœืฉื—ืจื•ืจ ื›ืคื•ืœ ืฉืœ ืžื‘ื ื™ ื ืชื•ื ื™ื.

ื“ื™ื•ืŸ ื”ืชื™ืงื•ืŸ ืžืฆื™ื™ืŸ ืฉื”ื‘ืขื™ื” ืœื ื ืคืชืจื” ืœื—ืœื•ื˜ื™ืŸ, ื•ื‘ืชื ืื™ื ืฉื”ืฉืชื ื• ืžืขื˜, ืžืžืฉื™ื›ื” ืœื”ื•ืคื™ืข ื‘ืขื“ื›ื•ื ื™ื ืฉืคื•ืจืกืžื•. ื”ื ื™ืชื•ื— ื”ืจืื” ืฉื”ืชื™ืงื•ืŸ ืžื›ืกื” ืจืง ืื—ื“ ืžื”ืžืงืจื™ื ื”ืžื™ื•ื—ื“ื™ื - ื›ืืฉืจ ื”ืฉืจืฉื•ืจ ื ืžืฆื ื‘ืžืฆื‘ ืงืจื™ืื”, ืืš ืื™ื ื• ืœื•ืงื— ื‘ื—ืฉื‘ื•ืŸ ืžืฆื‘ื™ ืฉืจืฉื•ืจ ืื—ืจื™ื (ืงืจื™ืื” ื•ื”ืฉื”ื™ื™ื”, ื”ืฉื”ื™ื™ื” ื•ืกื•ื’ื™ ื›ืชื™ื‘ื” ืžืกื•ื™ืžื™ื).

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”