Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 35

Количество 35

fstec логотип

BDU:2023-04930

больше 3 лет назад

Уязвимость функции generateKeys() программной платформы Node.js, позволяющая нарушителю обойти существующие ограничения безопасности

CVSS3: 5.3
EPSS: Низкий
altlinux логотип

ALT-PU-2023-4642

около 3 лет назад

ALT-PU-2023-4642: package `node` update to version 18.17.0-alt1

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20240916-03

около 2 лет назад

Множественные уязвимости nodejs

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2023-30590

почти 3 года назад

The generateKeys() API function returned from crypto.createDiffieHellman() only generates missing (or outdated) keys, that is, it only generates a private key if none has been set yet, but the function is also needed to compute the corresponding public key after calling setPrivateKey(). However, the documentation says this API call: "Generates private and public Diffie-Hellman key values". The documented behavior is very different from the actual behavior, and this difference could easily lead to security issues in applications that use these APIs as the DiffieHellman may be used as the basis for application-level security, implications are consequently broad.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2023-30590

больше 3 лет назад

The generateKeys() API function returned from crypto.createDiffieHellman() only generates missing (or outdated) keys, that is, it only generates a private key if none has been set yet, but the function is also needed to compute the corresponding public key after calling setPrivateKey(). However, the documentation says this API call: "Generates private and public Diffie-Hellman key values". The documented behavior is very different from the actual behavior, and this difference could easily lead to security issues in applications that use these APIs as the DiffieHellman may be used as the basis for application-level security, implications are consequently broad.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2023-30590

почти 3 года назад

The generateKeys() API function returned from crypto.createDiffieHellman() only generates missing (or outdated) keys, that is, it only generates a private key if none has been set yet, but the function is also needed to compute the corresponding public key after calling setPrivateKey(). However, the documentation says this API call: "Generates private and public Diffie-Hellman key values". The documented behavior is very different from the actual behavior, and this difference could easily lead to security issues in applications that use these APIs as the DiffieHellman may be used as the basis for application-level security, implications are consequently broad.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2023-30590

почти 3 года назад

The generateKeys() API function returned from crypto.createDiffieHellm ...

CVSS3: 7.5
EPSS: Низкий
altlinux логотип

ALT-PU-2025-2007

больше 1 года назад

ALT-PU-2025-2007: package `node` update to version 16.20.3-alt1

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-v63h-9gvh-2x49

почти 3 года назад

The generateKeys() API function returned from crypto.createDiffieHellman() only generates missing (or outdated) keys, that is, it only generates a private key if none has been set yet, but the function is also needed to compute the corresponding public key after calling setPrivateKey(). However, the documentation says this API call: "Generates private and public Diffie-Hellman key values". The documented behavior is very different from the actual behavior, and this difference could easily lead to security issues in applications that use these APIs as the DiffieHellman may be used as the basis for application-level security, implications are consequently broad.

CVSS3: 7.5
EPSS: Низкий
rocky логотип

RLSA-2023:4537

около 3 лет назад

Moderate: nodejs:16 security, bug fix, and enhancement update

EPSS: Низкий
rocky логотип

RLSA-2023:4536

почти 3 года назад

Moderate: nodejs:18 security, bug fix, and enhancement update

EPSS: Низкий
oracle-oval логотип

ELSA-2023-4537

около 3 лет назад

ELSA-2023-4537: nodejs:16 security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-4536

около 3 лет назад

ELSA-2023-4536: nodejs:18 security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-4331

около 3 лет назад

ELSA-2023-4331: nodejs security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-4330

около 3 лет назад

ELSA-2023-4330: 18 security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-12944

почти 3 года назад

ELSA-2023-12944: GraalVM Security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-12943

почти 3 года назад

ELSA-2023-12943: GraalVM Security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-12942

почти 3 года назад

ELSA-2023-12942: GraalVM Security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-12941

почти 3 года назад

ELSA-2023-12941: GraalVM Security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-12940

почти 3 года назад

ELSA-2023-12940: GraalVM Security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2023-04930

Уязвимость функции generateKeys() программной платформы Node.js, позволяющая нарушителю обойти существующие ограничения безопасности

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
altlinux логотип
ALT-PU-2023-4642

ALT-PU-2023-4642: package `node` update to version 18.17.0-alt1

CVSS3: 7.5
около 3 лет назад
redos логотип
ROS-20240916-03

Множественные уязвимости nodejs

CVSS3: 7.5
около 2 лет назад
ubuntu логотип
CVE-2023-30590

The generateKeys() API function returned from crypto.createDiffieHellman() only generates missing (or outdated) keys, that is, it only generates a private key if none has been set yet, but the function is also needed to compute the corresponding public key after calling setPrivateKey(). However, the documentation says this API call: "Generates private and public Diffie-Hellman key values". The documented behavior is very different from the actual behavior, and this difference could easily lead to security issues in applications that use these APIs as the DiffieHellman may be used as the basis for application-level security, implications are consequently broad.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
redhat логотип
CVE-2023-30590

The generateKeys() API function returned from crypto.createDiffieHellman() only generates missing (or outdated) keys, that is, it only generates a private key if none has been set yet, but the function is also needed to compute the corresponding public key after calling setPrivateKey(). However, the documentation says this API call: "Generates private and public Diffie-Hellman key values". The documented behavior is very different from the actual behavior, and this difference could easily lead to security issues in applications that use these APIs as the DiffieHellman may be used as the basis for application-level security, implications are consequently broad.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2023-30590

The generateKeys() API function returned from crypto.createDiffieHellman() only generates missing (or outdated) keys, that is, it only generates a private key if none has been set yet, but the function is also needed to compute the corresponding public key after calling setPrivateKey(). However, the documentation says this API call: "Generates private and public Diffie-Hellman key values". The documented behavior is very different from the actual behavior, and this difference could easily lead to security issues in applications that use these APIs as the DiffieHellman may be used as the basis for application-level security, implications are consequently broad.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
debian логотип
CVE-2023-30590

The generateKeys() API function returned from crypto.createDiffieHellm ...

CVSS3: 7.5
1%
Низкий
почти 3 года назад
altlinux логотип
ALT-PU-2025-2007

ALT-PU-2025-2007: package `node` update to version 16.20.3-alt1

CVSS3: 9.8
больше 1 года назад
github логотип
GHSA-v63h-9gvh-2x49

The generateKeys() API function returned from crypto.createDiffieHellman() only generates missing (or outdated) keys, that is, it only generates a private key if none has been set yet, but the function is also needed to compute the corresponding public key after calling setPrivateKey(). However, the documentation says this API call: "Generates private and public Diffie-Hellman key values". The documented behavior is very different from the actual behavior, and this difference could easily lead to security issues in applications that use these APIs as the DiffieHellman may be used as the basis for application-level security, implications are consequently broad.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
rocky логотип
RLSA-2023:4537

Moderate: nodejs:16 security, bug fix, and enhancement update

около 3 лет назад
rocky логотип
RLSA-2023:4536

Moderate: nodejs:18 security, bug fix, and enhancement update

почти 3 года назад
oracle-oval логотип
ELSA-2023-4537

ELSA-2023-4537: nodejs:16 security, bug fix, and enhancement update (MODERATE)

около 3 лет назад
oracle-oval логотип
ELSA-2023-4536

ELSA-2023-4536: nodejs:18 security, bug fix, and enhancement update (MODERATE)

около 3 лет назад
oracle-oval логотип
ELSA-2023-4331

ELSA-2023-4331: nodejs security, bug fix, and enhancement update (MODERATE)

около 3 лет назад
oracle-oval логотип
ELSA-2023-4330

ELSA-2023-4330: 18 security, bug fix, and enhancement update (MODERATE)

около 3 лет назад
oracle-oval логотип
ELSA-2023-12944

ELSA-2023-12944: GraalVM Security update (IMPORTANT)

почти 3 года назад
oracle-oval логотип
ELSA-2023-12943

ELSA-2023-12943: GraalVM Security update (IMPORTANT)

почти 3 года назад
oracle-oval логотип
ELSA-2023-12942

ELSA-2023-12942: GraalVM Security update (IMPORTANT)

почти 3 года назад
oracle-oval логотип
ELSA-2023-12941

ELSA-2023-12941: GraalVM Security update (IMPORTANT)

почти 3 года назад
oracle-oval логотип
ELSA-2023-12940

ELSA-2023-12940: GraalVM Security update (IMPORTANT)

почти 3 года назад

Уязвимостей на страницу