Количество 31
Количество 31

BDU:2023-04930
Уязвимость функции generateKeys() программной платформы Node.js, позволяющая нарушителю обойти существующие ограничения безопасности

ROS-20240916-03
Множественные уязвимости nodejs

CVE-2023-30590
The generateKeys() API function returned from crypto.createDiffieHellman() only generates missing (or outdated) keys, that is, it only generates a private key if none has been set yet, but the function is also needed to compute the corresponding public key after calling setPrivateKey(). However, the documentation says this API call: "Generates private and public Diffie-Hellman key values". The documented behavior is very different from the actual behavior, and this difference could easily lead to security issues in applications that use these APIs as the DiffieHellman may be used as the basis for application-level security, implications are consequently broad.

CVE-2023-30590
The generateKeys() API function returned from crypto.createDiffieHellman() only generates missing (or outdated) keys, that is, it only generates a private key if none has been set yet, but the function is also needed to compute the corresponding public key after calling setPrivateKey(). However, the documentation says this API call: "Generates private and public Diffie-Hellman key values". The documented behavior is very different from the actual behavior, and this difference could easily lead to security issues in applications that use these APIs as the DiffieHellman may be used as the basis for application-level security, implications are consequently broad.

CVE-2023-30590
The generateKeys() API function returned from crypto.createDiffieHellman() only generates missing (or outdated) keys, that is, it only generates a private key if none has been set yet, but the function is also needed to compute the corresponding public key after calling setPrivateKey(). However, the documentation says this API call: "Generates private and public Diffie-Hellman key values". The documented behavior is very different from the actual behavior, and this difference could easily lead to security issues in applications that use these APIs as the DiffieHellman may be used as the basis for application-level security, implications are consequently broad.
CVE-2023-30590
The generateKeys() API function returned from crypto.createDiffieHellm ...
GHSA-v63h-9gvh-2x49
The generateKeys() API function returned from crypto.createDiffieHellman() only generates missing (or outdated) keys, that is, it only generates a private key if none has been set yet, but the function is also needed to compute the corresponding public key after calling setPrivateKey(). However, the documentation says this API call: "Generates private and public Diffie-Hellman key values". The documented behavior is very different from the actual behavior, and this difference could easily lead to security issues in applications that use these APIs as the DiffieHellman may be used as the basis for application-level security, implications are consequently broad.
ELSA-2023-4537
ELSA-2023-4537: nodejs:16 security, bug fix, and enhancement update (MODERATE)
ELSA-2023-4536
ELSA-2023-4536: nodejs:18 security, bug fix, and enhancement update (MODERATE)
ELSA-2023-4331
ELSA-2023-4331: nodejs security, bug fix, and enhancement update (MODERATE)
ELSA-2023-4330
ELSA-2023-4330: 18 security, bug fix, and enhancement update (MODERATE)
ELSA-2023-12944
ELSA-2023-12944: GraalVM Security update (IMPORTANT)
ELSA-2023-12943
ELSA-2023-12943: GraalVM Security update (IMPORTANT)
ELSA-2023-12942
ELSA-2023-12942: GraalVM Security update (IMPORTANT)
ELSA-2023-12941
ELSA-2023-12941: GraalVM Security update (IMPORTANT)
ELSA-2023-12940
ELSA-2023-12940: GraalVM Security update (IMPORTANT)
ELSA-2023-12939
ELSA-2023-12939: GraalVM Security update (IMPORTANT)
ELSA-2023-12938
ELSA-2023-12938: GraalVM Security update (IMPORTANT)
ELSA-2023-12937
ELSA-2023-12937: GraalVM Security update (IMPORTANT)
ELSA-2023-12936
ELSA-2023-12936: GraalVM Security update (IMPORTANT)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | BDU:2023-04930 Уязвимость функции generateKeys() программной платформы Node.js, позволяющая нарушителю обойти существующие ограничения безопасности | CVSS3: 5.3 | 1% Низкий | почти 2 года назад |
![]() | ROS-20240916-03 Множественные уязвимости nodejs | CVSS3: 7.5 | 9 месяцев назад | |
![]() | CVE-2023-30590 The generateKeys() API function returned from crypto.createDiffieHellman() only generates missing (or outdated) keys, that is, it only generates a private key if none has been set yet, but the function is also needed to compute the corresponding public key after calling setPrivateKey(). However, the documentation says this API call: "Generates private and public Diffie-Hellman key values". The documented behavior is very different from the actual behavior, and this difference could easily lead to security issues in applications that use these APIs as the DiffieHellman may be used as the basis for application-level security, implications are consequently broad. | CVSS3: 7.5 | 1% Низкий | больше 1 года назад |
![]() | CVE-2023-30590 The generateKeys() API function returned from crypto.createDiffieHellman() only generates missing (or outdated) keys, that is, it only generates a private key if none has been set yet, but the function is also needed to compute the corresponding public key after calling setPrivateKey(). However, the documentation says this API call: "Generates private and public Diffie-Hellman key values". The documented behavior is very different from the actual behavior, and this difference could easily lead to security issues in applications that use these APIs as the DiffieHellman may be used as the basis for application-level security, implications are consequently broad. | CVSS3: 7.5 | 1% Низкий | почти 2 года назад |
![]() | CVE-2023-30590 The generateKeys() API function returned from crypto.createDiffieHellman() only generates missing (or outdated) keys, that is, it only generates a private key if none has been set yet, but the function is also needed to compute the corresponding public key after calling setPrivateKey(). However, the documentation says this API call: "Generates private and public Diffie-Hellman key values". The documented behavior is very different from the actual behavior, and this difference could easily lead to security issues in applications that use these APIs as the DiffieHellman may be used as the basis for application-level security, implications are consequently broad. | CVSS3: 7.5 | 1% Низкий | больше 1 года назад |
CVE-2023-30590 The generateKeys() API function returned from crypto.createDiffieHellm ... | CVSS3: 7.5 | 1% Низкий | больше 1 года назад | |
GHSA-v63h-9gvh-2x49 The generateKeys() API function returned from crypto.createDiffieHellman() only generates missing (or outdated) keys, that is, it only generates a private key if none has been set yet, but the function is also needed to compute the corresponding public key after calling setPrivateKey(). However, the documentation says this API call: "Generates private and public Diffie-Hellman key values". The documented behavior is very different from the actual behavior, and this difference could easily lead to security issues in applications that use these APIs as the DiffieHellman may be used as the basis for application-level security, implications are consequently broad. | CVSS3: 7.5 | 1% Низкий | больше 1 года назад | |
ELSA-2023-4537 ELSA-2023-4537: nodejs:16 security, bug fix, and enhancement update (MODERATE) | почти 2 года назад | |||
ELSA-2023-4536 ELSA-2023-4536: nodejs:18 security, bug fix, and enhancement update (MODERATE) | почти 2 года назад | |||
ELSA-2023-4331 ELSA-2023-4331: nodejs security, bug fix, and enhancement update (MODERATE) | почти 2 года назад | |||
ELSA-2023-4330 ELSA-2023-4330: 18 security, bug fix, and enhancement update (MODERATE) | почти 2 года назад | |||
ELSA-2023-12944 ELSA-2023-12944: GraalVM Security update (IMPORTANT) | больше 1 года назад | |||
ELSA-2023-12943 ELSA-2023-12943: GraalVM Security update (IMPORTANT) | больше 1 года назад | |||
ELSA-2023-12942 ELSA-2023-12942: GraalVM Security update (IMPORTANT) | больше 1 года назад | |||
ELSA-2023-12941 ELSA-2023-12941: GraalVM Security update (IMPORTANT) | больше 1 года назад | |||
ELSA-2023-12940 ELSA-2023-12940: GraalVM Security update (IMPORTANT) | больше 1 года назад | |||
ELSA-2023-12939 ELSA-2023-12939: GraalVM Security update (IMPORTANT) | больше 1 года назад | |||
ELSA-2023-12938 ELSA-2023-12938: GraalVM Security update (IMPORTANT) | больше 1 года назад | |||
ELSA-2023-12937 ELSA-2023-12937: GraalVM Security update (IMPORTANT) | больше 1 года назад | |||
ELSA-2023-12936 ELSA-2023-12936: GraalVM Security update (IMPORTANT) | больше 1 года назад |
Уязвимостей на страницу