Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Node.js

Node.jsпрограммная платформа, основанная на движке V8 (компилирующем JavaScript в машинный код)

Релизный цикл, информация об уязвимостях

Продукт: Node.js
Вендор: nodejs

График релизов

22232425262024202520262027202820292030

Релизные элементы

KBВерсияБилдДата доступности
24.18.124.18.1
24.18.024.18.0
24.17.024.17.0
24.16.024.16.0
24.15.024.15.0
24.14.124.14.1
24.14.024.14.0
24.13.124.13.1
24.13.024.13.0
24.12.024.12.0

Показывать по

Недавние уязвимости Node.js

Количество 1 203

oracle-oval логотип

ELSA-2022-4899

около 4 лет назад

ELSA-2022-4899: compat-openssl11 security and bug fix update (IMPORTANT)

EPSS: Высокий
rocky логотип

RLSA-2022:5326

около 4 лет назад

Low: compat-openssl10 security update

EPSS: Высокий
rocky логотип

RLSA-2022:4899

около 4 лет назад

Important: compat-openssl11 security and bug fix update

EPSS: Высокий
github логотип

GHSA-2w6h-7cgj-qw4q

около 4 лет назад

Node.js bad

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-hghm-3vc3-hppj

около 4 лет назад

A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality and integrity as well as system availability.

CVSS3: 5.6
EPSS: Низкий
github логотип

GHSA-7r9p-c88x-w357

около 4 лет назад

Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation of host names returned by Domain Name Servers in Node.js dns library which can lead to output of wrong hostnames (leading to Domain Hijacking) and injection vulnerabilities in applications using the library.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-9mvv-4q4j-q2j8

около 4 лет назад

If the Node.js https API was used incorrectly and "undefined" was in passed for the "rejectUnauthorized" parameter, no error was returned and connections to servers with an expired certificate would have been accepted.

CVSS3: 5.3
EPSS: Средний
github логотип

GHSA-6hhj-4h22-mrmm

около 4 лет назад

Node.js before 16.6.1, 14.17.5, and 12.22.5 is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption, to change process behavior.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-mjgw-69fr-p4h2

около 4 лет назад

Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This leads to a leak of file descriptors. If a file descriptor limit is configured on the system, then the server is unable to accept new connections and prevent the process also from opening, e.g. a file. If no file descriptor limit is configured, then this lead to an excessive memory usage and cause the system to run out of memory.

CVSS3: 7.5
EPSS: Высокий
github логотип

GHSA-f33f-hhx9-6j4m

около 4 лет назад

Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 allow two copies of a header field in an HTTP request (for example, two Transfer-Encoding header fields). In this case, Node.js identifies the first header field and ignores the second. This can lead to HTTP Request Smuggling.

CVSS3: 6.5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
oracle-oval логотип
ELSA-2022-4899

ELSA-2022-4899: compat-openssl11 security and bug fix update (IMPORTANT)

71%
Высокий
около 4 лет назад
rocky логотип
RLSA-2022:5326

Low: compat-openssl10 security update

71%
Высокий
около 4 лет назад
rocky логотип
RLSA-2022:4899

Important: compat-openssl11 security and bug fix update

71%
Высокий
около 4 лет назад
github логотип
CVSS3: 7.5
32%
Средний
около 4 лет назад
github логотип
GHSA-hghm-3vc3-hppj

A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality and integrity as well as system availability.

CVSS3: 5.6
3%
Низкий
около 4 лет назад
github логотип
GHSA-7r9p-c88x-w357

Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation of host names returned by Domain Name Servers in Node.js dns library which can lead to output of wrong hostnames (leading to Domain Hijacking) and injection vulnerabilities in applications using the library.

CVSS3: 9.8
22%
Средний
около 4 лет назад
github логотип
GHSA-9mvv-4q4j-q2j8

If the Node.js https API was used incorrectly and "undefined" was in passed for the "rejectUnauthorized" parameter, no error was returned and connections to servers with an expired certificate would have been accepted.

CVSS3: 5.3
15%
Средний
около 4 лет назад
github логотип
GHSA-6hhj-4h22-mrmm

Node.js before 16.6.1, 14.17.5, and 12.22.5 is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption, to change process behavior.

CVSS3: 7.5
14%
Средний
около 4 лет назад
github логотип
GHSA-mjgw-69fr-p4h2

Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This leads to a leak of file descriptors. If a file descriptor limit is configured on the system, then the server is unable to accept new connections and prevent the process also from opening, e.g. a file. If no file descriptor limit is configured, then this lead to an excessive memory usage and cause the system to run out of memory.

CVSS3: 7.5
74%
Высокий
около 4 лет назад
github логотип
GHSA-f33f-hhx9-6j4m

Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 allow two copies of a header field in an HTTP request (for example, two Transfer-Encoding header fields). In this case, Node.js identifies the first header field and ignores the second. This can lead to HTTP Request Smuggling.

CVSS3: 6.5
16%
Средний
около 4 лет назад

Уязвимостей на страницу


Поделиться