Количество 36
Количество 36
CVE-2024-36137
A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-write flag is used. Node.js Permission Model do not operate on file descriptors, however, operations such as fs.fchown or fs.fchmod can use a "read-only" file descriptor to change the owner and permissions of a file.
CVE-2024-36137
A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-write flag is used. Node.js Permission Model do not operate on file descriptors, however, operations such as fs.fchown or fs.fchmod can use a "read-only" file descriptor to change the owner and permissions of a file.
CVE-2024-36137
A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-write flag is used. Node.js Permission Model do not operate on file descriptors, however, operations such as fs.fchown or fs.fchmod can use a "read-only" file descriptor to change the owner and permissions of a file.
CVE-2024-36137
A vulnerability has been identified in Node.js, affecting users of the ...
CVE-2024-28863
node-tar is a Tar for Node.js. node-tar prior to version 6.2.1 has no limit on the number of sub-folders created in the folder creation process. An attacker who generates a large number of sub-folders can consume memory on the system running node-tar and even crash the Node.js client within few seconds of running it using a path with too many sub-folders inside. Version 6.2.1 fixes this issue by preventing extraction in excessively deep sub-folders.
CVE-2024-28863
node-tar is a Tar for Node.js. node-tar prior to version 6.2.1 has no limit on the number of sub-folders created in the folder creation process. An attacker who generates a large number of sub-folders can consume memory on the system running node-tar and even crash the Node.js client within few seconds of running it using a path with too many sub-folders inside. Version 6.2.1 fixes this issue by preventing extraction in excessively deep sub-folders.
CVE-2024-28863
node-tar is a Tar for Node.js. node-tar prior to version 6.2.1 has no limit on the number of sub-folders created in the folder creation process. An attacker who generates a large number of sub-folders can consume memory on the system running node-tar and even crash the Node.js client within few seconds of running it using a path with too many sub-folders inside. Version 6.2.1 fixes this issue by preventing extraction in excessively deep sub-folders.
CVE-2024-28863
CVE-2024-28863
node-tar is a Tar for Node.js. node-tar prior to version 6.2.1 has no ...
SUSE-SU-2024:2542-1
Security update for nodejs18
SUSE-SU-2024:2496-1
Security update for nodejs18
GHSA-q793-mj5v-wh68
A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-write flag is used. Node.js Permission Model do not operate on file descriptors, however, operations such as fs.fchown or fs.fchmod can use a "read-only" file descriptor to change the owner and permissions of a file.
BDU:2024-05685
Уязвимость компонента Permission Model программной платформы Node.js, позволяющая нарушителю оказать воздействие на конфиденциальность и целостность защищаемой информации
GHSA-f5x3-32g6-xq36
Denial of service while parsing a tar file due to lack of folders count validation
BDU:2024-09418
Уязвимость модуля node-tar библиотеки Node.js, позволяющая нарушителю вызвать отказ в обслуживании
ROS-20241029-08
Множественные уязвимости opensearch
Уязвимостей на страницу
Уязвимость  | CVSS  | EPSS  | Опубликовано  | |
|---|---|---|---|---|
CVE-2024-36137 A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-write flag is used. Node.js Permission Model do not operate on file descriptors, however, operations such as fs.fchown or fs.fchmod can use a "read-only" file descriptor to change the owner and permissions of a file.  | CVSS3: 3.3  | 0% Низкий | около 1 года назад | |
CVE-2024-36137 A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-write flag is used. Node.js Permission Model do not operate on file descriptors, however, operations such as fs.fchown or fs.fchmod can use a "read-only" file descriptor to change the owner and permissions of a file.  | CVSS3: 3.9  | 0% Низкий | больше 1 года назад | |
CVE-2024-36137 A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-write flag is used. Node.js Permission Model do not operate on file descriptors, however, operations such as fs.fchown or fs.fchmod can use a "read-only" file descriptor to change the owner and permissions of a file.  | CVSS3: 3.3  | 0% Низкий | около 1 года назад | |
CVE-2024-36137 A vulnerability has been identified in Node.js, affecting users of the ...  | CVSS3: 3.3  | 0% Низкий | около 1 года назад | |
CVE-2024-28863 node-tar is a Tar for Node.js. node-tar prior to version 6.2.1 has no limit on the number of sub-folders created in the folder creation process. An attacker who generates a large number of sub-folders can consume memory on the system running node-tar and even crash the Node.js client within few seconds of running it using a path with too many sub-folders inside. Version 6.2.1 fixes this issue by preventing extraction in excessively deep sub-folders.  | CVSS3: 6.5  | 0% Низкий | больше 1 года назад | |
CVE-2024-28863 node-tar is a Tar for Node.js. node-tar prior to version 6.2.1 has no limit on the number of sub-folders created in the folder creation process. An attacker who generates a large number of sub-folders can consume memory on the system running node-tar and even crash the Node.js client within few seconds of running it using a path with too many sub-folders inside. Version 6.2.1 fixes this issue by preventing extraction in excessively deep sub-folders.  | CVSS3: 6.5  | 0% Низкий | больше 1 года назад | |
CVE-2024-28863 node-tar is a Tar for Node.js. node-tar prior to version 6.2.1 has no limit on the number of sub-folders created in the folder creation process. An attacker who generates a large number of sub-folders can consume memory on the system running node-tar and even crash the Node.js client within few seconds of running it using a path with too many sub-folders inside. Version 6.2.1 fixes this issue by preventing extraction in excessively deep sub-folders.  | CVSS3: 6.5  | 0% Низкий | больше 1 года назад | |
CVSS3: 6.5  | 0% Низкий | больше 1 года назад | ||
CVE-2024-28863 node-tar is a Tar for Node.js. node-tar prior to version 6.2.1 has no ...  | CVSS3: 6.5  | 0% Низкий | больше 1 года назад | |
SUSE-SU-2024:2542-1 Security update for nodejs18  | больше 1 года назад | |||
SUSE-SU-2024:2496-1 Security update for nodejs18  | больше 1 года назад | |||
GHSA-q793-mj5v-wh68 A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-write flag is used. Node.js Permission Model do not operate on file descriptors, however, operations such as fs.fchown or fs.fchmod can use a "read-only" file descriptor to change the owner and permissions of a file.  | CVSS3: 3.3  | 0% Низкий | около 1 года назад | |
BDU:2024-05685 Уязвимость компонента Permission Model программной платформы Node.js, позволяющая нарушителю оказать воздействие на конфиденциальность и целостность защищаемой информации  | CVSS3: 3.9  | 0% Низкий | больше 1 года назад | |
GHSA-f5x3-32g6-xq36 Denial of service while parsing a tar file due to lack of folders count validation  | CVSS3: 6.5  | 0% Низкий | больше 1 года назад | |
BDU:2024-09418 Уязвимость модуля node-tar библиотеки Node.js, позволяющая нарушителю вызвать отказ в обслуживании  | CVSS3: 6.5  | 0% Низкий | больше 1 года назад | |
ROS-20241029-08 Множественные уязвимости opensearch  | CVSS3: 7.5  | около 1 года назад | 
Уязвимостей на страницу