Логотип exploitDog
bind: "CVE-2023-30590"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2023-30590"

Количество 31

Количество 31

ubuntu логотип

CVE-2023-30590

больше 1 года назад

The generateKeys() API function returned from crypto.createDiffieHellman() only generates missing (or outdated) keys, that is, it only generates a private key if none has been set yet, but the function is also needed to compute the corresponding public key after calling setPrivateKey(). However, the documentation says this API call: "Generates private and public Diffie-Hellman key values". The documented behavior is very different from the actual behavior, and this difference could easily lead to security issues in applications that use these APIs as the DiffieHellman may be used as the basis for application-level security, implications are consequently broad.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2023-30590

около 2 лет назад

The generateKeys() API function returned from crypto.createDiffieHellman() only generates missing (or outdated) keys, that is, it only generates a private key if none has been set yet, but the function is also needed to compute the corresponding public key after calling setPrivateKey(). However, the documentation says this API call: "Generates private and public Diffie-Hellman key values". The documented behavior is very different from the actual behavior, and this difference could easily lead to security issues in applications that use these APIs as the DiffieHellman may be used as the basis for application-level security, implications are consequently broad.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2023-30590

больше 1 года назад

The generateKeys() API function returned from crypto.createDiffieHellman() only generates missing (or outdated) keys, that is, it only generates a private key if none has been set yet, but the function is also needed to compute the corresponding public key after calling setPrivateKey(). However, the documentation says this API call: "Generates private and public Diffie-Hellman key values". The documented behavior is very different from the actual behavior, and this difference could easily lead to security issues in applications that use these APIs as the DiffieHellman may be used as the basis for application-level security, implications are consequently broad.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2023-30590

больше 1 года назад

The generateKeys() API function returned from crypto.createDiffieHellm ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-v63h-9gvh-2x49

больше 1 года назад

The generateKeys() API function returned from crypto.createDiffieHellman() only generates missing (or outdated) keys, that is, it only generates a private key if none has been set yet, but the function is also needed to compute the corresponding public key after calling setPrivateKey(). However, the documentation says this API call: "Generates private and public Diffie-Hellman key values". The documented behavior is very different from the actual behavior, and this difference could easily lead to security issues in applications that use these APIs as the DiffieHellman may be used as the basis for application-level security, implications are consequently broad.

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2023-04930

около 2 лет назад

Уязвимость функции generateKeys() программной платформы Node.js, позволяющая нарушителю обойти существующие ограничения безопасности

CVSS3: 5.3
EPSS: Низкий
oracle-oval логотип

ELSA-2023-4537

почти 2 года назад

ELSA-2023-4537: nodejs:16 security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-4536

почти 2 года назад

ELSA-2023-4536: nodejs:18 security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-4331

около 2 лет назад

ELSA-2023-4331: nodejs security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-4330

около 2 лет назад

ELSA-2023-4330: 18 security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-12944

почти 2 года назад

ELSA-2023-12944: GraalVM Security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-12943

почти 2 года назад

ELSA-2023-12943: GraalVM Security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-12942

почти 2 года назад

ELSA-2023-12942: GraalVM Security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-12941

почти 2 года назад

ELSA-2023-12941: GraalVM Security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-12940

почти 2 года назад

ELSA-2023-12940: GraalVM Security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-12939

почти 2 года назад

ELSA-2023-12939: GraalVM Security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-12938

почти 2 года назад

ELSA-2023-12938: GraalVM Security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-12937

почти 2 года назад

ELSA-2023-12937: GraalVM Security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-12936

почти 2 года назад

ELSA-2023-12936: GraalVM Security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-12935

почти 2 года назад

ELSA-2023-12935: GraalVM Security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-30590

The generateKeys() API function returned from crypto.createDiffieHellman() only generates missing (or outdated) keys, that is, it only generates a private key if none has been set yet, but the function is also needed to compute the corresponding public key after calling setPrivateKey(). However, the documentation says this API call: "Generates private and public Diffie-Hellman key values". The documented behavior is very different from the actual behavior, and this difference could easily lead to security issues in applications that use these APIs as the DiffieHellman may be used as the basis for application-level security, implications are consequently broad.

CVSS3: 7.5
1%
Низкий
больше 1 года назад
redhat логотип
CVE-2023-30590

The generateKeys() API function returned from crypto.createDiffieHellman() only generates missing (or outdated) keys, that is, it only generates a private key if none has been set yet, but the function is also needed to compute the corresponding public key after calling setPrivateKey(). However, the documentation says this API call: "Generates private and public Diffie-Hellman key values". The documented behavior is very different from the actual behavior, and this difference could easily lead to security issues in applications that use these APIs as the DiffieHellman may be used as the basis for application-level security, implications are consequently broad.

CVSS3: 7.5
1%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-30590

The generateKeys() API function returned from crypto.createDiffieHellman() only generates missing (or outdated) keys, that is, it only generates a private key if none has been set yet, but the function is also needed to compute the corresponding public key after calling setPrivateKey(). However, the documentation says this API call: "Generates private and public Diffie-Hellman key values". The documented behavior is very different from the actual behavior, and this difference could easily lead to security issues in applications that use these APIs as the DiffieHellman may be used as the basis for application-level security, implications are consequently broad.

CVSS3: 7.5
1%
Низкий
больше 1 года назад
debian логотип
CVE-2023-30590

The generateKeys() API function returned from crypto.createDiffieHellm ...

CVSS3: 7.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-v63h-9gvh-2x49

The generateKeys() API function returned from crypto.createDiffieHellman() only generates missing (or outdated) keys, that is, it only generates a private key if none has been set yet, but the function is also needed to compute the corresponding public key after calling setPrivateKey(). However, the documentation says this API call: "Generates private and public Diffie-Hellman key values". The documented behavior is very different from the actual behavior, and this difference could easily lead to security issues in applications that use these APIs as the DiffieHellman may be used as the basis for application-level security, implications are consequently broad.

CVSS3: 7.5
1%
Низкий
больше 1 года назад
fstec логотип
BDU:2023-04930

Уязвимость функции generateKeys() программной платформы Node.js, позволяющая нарушителю обойти существующие ограничения безопасности

CVSS3: 5.3
1%
Низкий
около 2 лет назад
oracle-oval логотип
ELSA-2023-4537

ELSA-2023-4537: nodejs:16 security, bug fix, and enhancement update (MODERATE)

почти 2 года назад
oracle-oval логотип
ELSA-2023-4536

ELSA-2023-4536: nodejs:18 security, bug fix, and enhancement update (MODERATE)

почти 2 года назад
oracle-oval логотип
ELSA-2023-4331

ELSA-2023-4331: nodejs security, bug fix, and enhancement update (MODERATE)

около 2 лет назад
oracle-oval логотип
ELSA-2023-4330

ELSA-2023-4330: 18 security, bug fix, and enhancement update (MODERATE)

около 2 лет назад
oracle-oval логотип
ELSA-2023-12944

ELSA-2023-12944: GraalVM Security update (IMPORTANT)

почти 2 года назад
oracle-oval логотип
ELSA-2023-12943

ELSA-2023-12943: GraalVM Security update (IMPORTANT)

почти 2 года назад
oracle-oval логотип
ELSA-2023-12942

ELSA-2023-12942: GraalVM Security update (IMPORTANT)

почти 2 года назад
oracle-oval логотип
ELSA-2023-12941

ELSA-2023-12941: GraalVM Security update (IMPORTANT)

почти 2 года назад
oracle-oval логотип
ELSA-2023-12940

ELSA-2023-12940: GraalVM Security update (IMPORTANT)

почти 2 года назад
oracle-oval логотип
ELSA-2023-12939

ELSA-2023-12939: GraalVM Security update (IMPORTANT)

почти 2 года назад
oracle-oval логотип
ELSA-2023-12938

ELSA-2023-12938: GraalVM Security update (IMPORTANT)

почти 2 года назад
oracle-oval логотип
ELSA-2023-12937

ELSA-2023-12937: GraalVM Security update (IMPORTANT)

почти 2 года назад
oracle-oval логотип
ELSA-2023-12936

ELSA-2023-12936: GraalVM Security update (IMPORTANT)

почти 2 года назад
oracle-oval логотип
ELSA-2023-12935

ELSA-2023-12935: GraalVM Security update (IMPORTANT)

почти 2 года назад

Уязвимостей на страницу