Логотип exploitDog
product: "node.js"
Консоль
Логотип exploitDog

exploitDog

product: "node.js"
Node.js

Node.jsпрограммная платформа, основанная на движке V8 (компилирующем JavaScript в машинный код)

Релизный цикл, информация об уязвимостях

Продукт: Node.js
Вендор: nodejs

График релизов

20212223242023202420252026202720282029

Недавние уязвимости Node.js

Количество 1 024

github логотип

GHSA-wff4-fpwg-qqv3

около 3 лет назад

Unexpected server crash in Next.js

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-fxfc-w6xq-5pp8

около 3 лет назад

A cryptographic vulnerability exists on Node.js on linux in versions of 18.x prior to 18.40.0 which allowed a default path for openssl.cnf that might be accessible under some circumstances to a non-admin user instead of /etc/ssl as was the case in versions prior to the upgrade to OpenSSL 3.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-5492-mr68-4m2h

около 3 лет назад

The llhttp parser in the http module in Node v17.6.0 does not correctly handle multi-line Transfer-Encoding headers. This can lead to HTTP Request Smuggling (HRS).

CVSS3: 9.1
EPSS: Высокий
github логотип

GHSA-fxjx-rf8x-pxw8

около 3 лет назад

Node.js is vulnerable to Hijack Execution Flow: DLL Hijacking under certain conditions on Windows platforms.This vulnerability can be exploited if the victim has the following dependencies on a Windows machine:* OpenSSL has been installed and “C:\Program Files\Common Files\SSL\openssl.cnf” exists.Whenever the above conditions are present, `node.exe` will search for `providers.dll` in the current user directory.After that, `node.exe` will try to search for `providers.dll` by the DLL Search Order in Windows.It is possible for an attacker to place the malicious file `providers.dll` under a variety of paths and exploit this vulnerability.

CVSS3: 7.3
EPSS: Средний
github логотип

GHSA-5689-v88g-g6rv

около 3 лет назад

llhttp allows HTTP Request Smuggling via Flawed Parsing of Transfer-Encoding

CVSS3: 9.1
EPSS: Высокий
github логотип

GHSA-q5vx-44v4-gch4

около 3 лет назад

llhttp allows HTTP Request Smuggling via Improper Delimiting of Header Fields

CVSS3: 9.1
EPSS: Средний
github логотип

GHSA-w95h-2gj2-x2p4

около 3 лет назад

A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding attacks.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2022-32223

около 3 лет назад

Node.js is vulnerable to Hijack Execution Flow: DLL Hijacking under certain conditions on Windows platforms.This vulnerability can be exploited if the victim has the following dependencies on a Windows machine:* OpenSSL has been installed and “C:\Program Files\Common Files\SSL\openssl.cnf” exists.Whenever the above conditions are present, `node.exe` will search for `providers.dll` in the current user directory.After that, `node.exe` will try to search for `providers.dll` by the DLL Search Order in Windows.It is possible for an attacker to place the malicious file `providers.dll` under a variety of paths and exploit this vulnerability.

CVSS3: 7.3
EPSS: Средний
debian логотип

CVE-2022-32223

около 3 лет назад

Node.js is vulnerable to Hijack Execution Flow: DLL Hijacking under ce ...

CVSS3: 7.3
EPSS: Средний
nvd логотип

CVE-2022-32222

около 3 лет назад

A cryptographic vulnerability exists on Node.js on linux in versions of 18.x prior to 18.40.0 which allowed a default path for openssl.cnf that might be accessible under some circumstances to a non-admin user instead of /etc/ssl as was the case in versions prior to the upgrade to OpenSSL 3.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-wff4-fpwg-qqv3

Unexpected server crash in Next.js

CVSS3: 5.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-fxfc-w6xq-5pp8

A cryptographic vulnerability exists on Node.js on linux in versions of 18.x prior to 18.40.0 which allowed a default path for openssl.cnf that might be accessible under some circumstances to a non-admin user instead of /etc/ssl as was the case in versions prior to the upgrade to OpenSSL 3.

CVSS3: 5.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-5492-mr68-4m2h

The llhttp parser in the http module in Node v17.6.0 does not correctly handle multi-line Transfer-Encoding headers. This can lead to HTTP Request Smuggling (HRS).

CVSS3: 9.1
88%
Высокий
около 3 лет назад
github логотип
GHSA-fxjx-rf8x-pxw8

Node.js is vulnerable to Hijack Execution Flow: DLL Hijacking under certain conditions on Windows platforms.This vulnerability can be exploited if the victim has the following dependencies on a Windows machine:* OpenSSL has been installed and “C:\Program Files\Common Files\SSL\openssl.cnf” exists.Whenever the above conditions are present, `node.exe` will search for `providers.dll` in the current user directory.After that, `node.exe` will try to search for `providers.dll` by the DLL Search Order in Windows.It is possible for an attacker to place the malicious file `providers.dll` under a variety of paths and exploit this vulnerability.

CVSS3: 7.3
10%
Средний
около 3 лет назад
github логотип
GHSA-5689-v88g-g6rv

llhttp allows HTTP Request Smuggling via Flawed Parsing of Transfer-Encoding

CVSS3: 9.1
89%
Высокий
около 3 лет назад
github логотип
GHSA-q5vx-44v4-gch4

llhttp allows HTTP Request Smuggling via Improper Delimiting of Header Fields

CVSS3: 9.1
65%
Средний
около 3 лет назад
github логотип
GHSA-w95h-2gj2-x2p4

A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding attacks.

CVSS3: 8.1
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-32223

Node.js is vulnerable to Hijack Execution Flow: DLL Hijacking under certain conditions on Windows platforms.This vulnerability can be exploited if the victim has the following dependencies on a Windows machine:* OpenSSL has been installed and “C:\Program Files\Common Files\SSL\openssl.cnf” exists.Whenever the above conditions are present, `node.exe` will search for `providers.dll` in the current user directory.After that, `node.exe` will try to search for `providers.dll` by the DLL Search Order in Windows.It is possible for an attacker to place the malicious file `providers.dll` under a variety of paths and exploit this vulnerability.

CVSS3: 7.3
10%
Средний
около 3 лет назад
debian логотип
CVE-2022-32223

Node.js is vulnerable to Hijack Execution Flow: DLL Hijacking under ce ...

CVSS3: 7.3
10%
Средний
около 3 лет назад
nvd логотип
CVE-2022-32222

A cryptographic vulnerability exists on Node.js on linux in versions of 18.x prior to 18.40.0 which allowed a default path for openssl.cnf that might be accessible under some circumstances to a non-admin user instead of /etc/ssl as was the case in versions prior to the upgrade to OpenSSL 3.

CVSS3: 5.3
0%
Низкий
около 3 лет назад

Уязвимостей на страницу


Поделиться