Количество 11
Количество 11

BDU:2023-03309
Уязвимость пакетного менеджера npm, связанная с раскрытием информации, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVE-2022-29244
npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace or with a workspace flag (ie. `--workspaces`, `--workspace=<name>`). Anyone who has run `npm pack` or `npm publish` inside a workspace, as of v7.9.0 and v7.13.0 respectively, may be affected and have published files into the npm registry they did not intend to include. Users should upgrade to the latest, patched version of npm v8.11.0, run: npm i -g npm@latest . Node.js versions v16.15.1, v17.19.1, and v18.3.0 include the patched v8.11.0 version of npm.

CVE-2022-29244
npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace or with a workspace flag (ie. `--workspaces`, `--workspace=<name>`). Anyone who has run `npm pack` or `npm publish` inside a workspace, as of v7.9.0 and v7.13.0 respectively, may be affected and have published files into the npm registry they did not intend to include. Users should upgrade to the latest, patched version of npm v8.11.0, run: npm i -g npm@latest . Node.js versions v16.15.1, v17.19.1, and v18.3.0 include the patched v8.11.0 version of npm.

CVE-2022-29244
npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace or with a workspace flag (ie. `--workspaces`, `--workspace=<name>`). Anyone who has run `npm pack` or `npm publish` inside a workspace, as of v7.9.0 and v7.13.0 respectively, may be affected and have published files into the npm registry they did not intend to include. Users should upgrade to the latest, patched version of npm v8.11.0, run: npm i -g npm@latest . Node.js versions v16.15.1, v17.19.1, and v18.3.0 include the patched v8.11.0 version of npm.

ROS-20230616-08
Уязвимость libuv

ROS-20230616-01
Уязвимость nodejs
GHSA-hj9c-8jmm-8c52
Packing does not respect root-level ignore files in workspaces

SUSE-SU-2022:3251-1
Security update for nodejs16

SUSE-SU-2022:3250-1
Security update for nodejs16

SUSE-SU-2022:3196-1
Security update for nodejs16
ELSA-2022-6595
ELSA-2022-6595: nodejs and nodejs-nodemon security and bug fix update (MODERATE)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | BDU:2023-03309 Уязвимость пакетного менеджера npm, связанная с раскрытием информации, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации | CVSS3: 7.5 | 1% Низкий | больше 2 лет назад |
![]() | CVE-2022-29244 npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace or with a workspace flag (ie. `--workspaces`, `--workspace=<name>`). Anyone who has run `npm pack` or `npm publish` inside a workspace, as of v7.9.0 and v7.13.0 respectively, may be affected and have published files into the npm registry they did not intend to include. Users should upgrade to the latest, patched version of npm v8.11.0, run: npm i -g npm@latest . Node.js versions v16.15.1, v17.19.1, and v18.3.0 include the patched v8.11.0 version of npm. | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад |
![]() | CVE-2022-29244 npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace or with a workspace flag (ie. `--workspaces`, `--workspace=<name>`). Anyone who has run `npm pack` or `npm publish` inside a workspace, as of v7.9.0 and v7.13.0 respectively, may be affected and have published files into the npm registry they did not intend to include. Users should upgrade to the latest, patched version of npm v8.11.0, run: npm i -g npm@latest . Node.js versions v16.15.1, v17.19.1, and v18.3.0 include the patched v8.11.0 version of npm. | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад |
![]() | CVE-2022-29244 npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace or with a workspace flag (ie. `--workspaces`, `--workspace=<name>`). Anyone who has run `npm pack` or `npm publish` inside a workspace, as of v7.9.0 and v7.13.0 respectively, may be affected and have published files into the npm registry they did not intend to include. Users should upgrade to the latest, patched version of npm v8.11.0, run: npm i -g npm@latest . Node.js versions v16.15.1, v17.19.1, and v18.3.0 include the patched v8.11.0 version of npm. | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад |
![]() | ROS-20230616-08 Уязвимость libuv | CVSS3: 7.5 | 1% Низкий | больше 2 лет назад |
![]() | ROS-20230616-01 Уязвимость nodejs | CVSS3: 7.5 | 1% Низкий | больше 2 лет назад |
GHSA-hj9c-8jmm-8c52 Packing does not respect root-level ignore files in workspaces | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад | |
![]() | SUSE-SU-2022:3251-1 Security update for nodejs16 | около 3 лет назад | ||
![]() | SUSE-SU-2022:3250-1 Security update for nodejs16 | около 3 лет назад | ||
![]() | SUSE-SU-2022:3196-1 Security update for nodejs16 | около 3 лет назад | ||
ELSA-2022-6595 ELSA-2022-6595: nodejs and nodejs-nodemon security and bug fix update (MODERATE) | около 3 лет назад |
Уязвимостей на страницу