Логотип exploitDog
product: "node.js"
Консоль
Логотип exploitDog

exploitDog

product: "node.js"
Node.js

Node.jsпрограммная платформа, основанная на движке V8 (компилирующем JavaScript в машинный код)

Релизный цикл, информация об уязвимостях

Продукт: Node.js
Вендор: nodejs

График релизов

20212223242023202420252026202720282029

Недавние уязвимости Node.js

Количество 1 024

nvd логотип

CVE-2023-23920

больше 2 лет назад

An untrusted search path vulnerability exists in Node.js. <19.6.1, <18.14.1, <16.19.1, and <14.21.3 that could allow an attacker to search and potentially load ICU data when running with elevated privileges.

CVSS3: 4.2
EPSS: Низкий
debian логотип

CVE-2023-23920

больше 2 лет назад

An untrusted search path vulnerability exists in Node.js. <19.6.1, <18 ...

CVSS3: 4.2
EPSS: Низкий
nvd логотип

CVE-2023-23919

больше 2 лет назад

A cryptographic vulnerability exists in Node.js <19.2.0, <18.14.1, <16.19.1, <14.21.3 that in some cases did does not clear the OpenSSL error stack after operations that may set it. This may lead to false positive errors during subsequent cryptographic operations that happen to be on the same thread. This in turn could be used to cause a denial of service.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2023-23919

больше 2 лет назад

A cryptographic vulnerability exists in Node.js <19.2.0, <18.14.1, <16 ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2023-23918

больше 2 лет назад

A privilege escalation vulnerability exists in Node.js <19.6.1, <18.14.1, <16.19.1 and <14.21.3 that made it possible to bypass the experimental Permissions (https://nodejs.org/api/permissions.html) feature in Node.js and access non authorized modules by using process.mainModule.require(). This only affects users who had enabled the experimental permissions option with --experimental-policy.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2023-23918

больше 2 лет назад

A privilege escalation vulnerability exists in Node.js <19.6.1, <18.14 ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2023-23920

больше 2 лет назад

An untrusted search path vulnerability exists in Node.js. <19.6.1, <18.14.1, <16.19.1, and <14.21.3 that could allow an attacker to search and potentially load ICU data when running with elevated privileges.

CVSS3: 4.2
EPSS: Низкий
ubuntu логотип

CVE-2023-23918

больше 2 лет назад

A privilege escalation vulnerability exists in Node.js <19.6.1, <18.14.1, <16.19.1 and <14.21.3 that made it possible to bypass the experimental Permissions (https://nodejs.org/api/permissions.html) feature in Node.js and access non authorized modules by using process.mainModule.require(). This only affects users who had enabled the experimental permissions option with --experimental-policy.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2023-23919

больше 2 лет назад

A cryptographic vulnerability exists in Node.js <19.2.0, <18.14.1, <16.19.1, <14.21.3 that in some cases did does not clear the OpenSSL error stack after operations that may set it. This may lead to false positive errors during subsequent cryptographic operations that happen to be on the same thread. This in turn could be used to cause a denial of service.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-5r9g-qh6m-jxff

больше 2 лет назад

CRLF Injection in Nodejs ‘undici’ via host

CVSS3: 4.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2023-23920

An untrusted search path vulnerability exists in Node.js. <19.6.1, <18.14.1, <16.19.1, and <14.21.3 that could allow an attacker to search and potentially load ICU data when running with elevated privileges.

CVSS3: 4.2
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-23920

An untrusted search path vulnerability exists in Node.js. <19.6.1, <18 ...

CVSS3: 4.2
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-23919

A cryptographic vulnerability exists in Node.js <19.2.0, <18.14.1, <16.19.1, <14.21.3 that in some cases did does not clear the OpenSSL error stack after operations that may set it. This may lead to false positive errors during subsequent cryptographic operations that happen to be on the same thread. This in turn could be used to cause a denial of service.

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-23919

A cryptographic vulnerability exists in Node.js <19.2.0, <18.14.1, <16 ...

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-23918

A privilege escalation vulnerability exists in Node.js <19.6.1, <18.14.1, <16.19.1 and <14.21.3 that made it possible to bypass the experimental Permissions (https://nodejs.org/api/permissions.html) feature in Node.js and access non authorized modules by using process.mainModule.require(). This only affects users who had enabled the experimental permissions option with --experimental-policy.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-23918

A privilege escalation vulnerability exists in Node.js <19.6.1, <18.14 ...

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-23920

An untrusted search path vulnerability exists in Node.js. <19.6.1, <18.14.1, <16.19.1, and <14.21.3 that could allow an attacker to search and potentially load ICU data when running with elevated privileges.

CVSS3: 4.2
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-23918

A privilege escalation vulnerability exists in Node.js <19.6.1, <18.14.1, <16.19.1 and <14.21.3 that made it possible to bypass the experimental Permissions (https://nodejs.org/api/permissions.html) feature in Node.js and access non authorized modules by using process.mainModule.require(). This only affects users who had enabled the experimental permissions option with --experimental-policy.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-23919

A cryptographic vulnerability exists in Node.js <19.2.0, <18.14.1, <16.19.1, <14.21.3 that in some cases did does not clear the OpenSSL error stack after operations that may set it. This may lead to false positive errors during subsequent cryptographic operations that happen to be on the same thread. This in turn could be used to cause a denial of service.

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-5r9g-qh6m-jxff

CRLF Injection in Nodejs ‘undici’ via host

CVSS3: 4.6
1%
Низкий
больше 2 лет назад

Уязвимостей на страницу


Поделиться