Описание
An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CON, PRN, and AUX. This vulnerability affects Windows users of path.join
API.
Релиз | Статус | Примечание |
---|---|---|
devel | not-affected | windows only |
esm-apps/bionic | not-affected | windows only |
esm-apps/focal | not-affected | windows only |
esm-apps/jammy | not-affected | windows only |
esm-apps/noble | not-affected | windows only |
esm-apps/xenial | not-affected | windows only |
esm-infra-legacy/trusty | not-affected | windows only |
jammy | not-affected | windows only |
noble | not-affected | windows only |
plucky | not-affected | windows only |
Показывать по
EPSS
7.5 High
CVSS3
Связанные уязвимости
An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CON, PRN, and AUX. This vulnerability affects Windows users of `path.join` API.
An incomplete fix has been identified for CVE-2025-23084 in Node.js, s ...
An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CON, PRN, and AUX. This vulnerability affects Windows users of `path.join` API.
Уязвимость функции path.normalize() программной платформы Node.js, позволяющая нарушителю оказать воздействие на конфиденциальность и целостность защищаемой информации
EPSS
7.5 High
CVSS3