Количество 38
Количество 38
BDU:2024-07321
Уязвимость функции IsIPAddress() программной платформы Node.js, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
ALT-PU-2022-2701
ALT-PU-2022-2701: package `node` update to version 16.17.1-alt1
ALT-PU-2022-3235
ALT-PU-2022-3235: package `node` update to version 14.21.1-alt1
ALT-PU-2023-1461
ALT-PU-2023-1461: package `node` update to version 16.18.1-alt1
CVE-2022-32212
A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding attacks.
CVE-2022-32212
A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding attacks.
CVE-2022-32212
A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding attacks.
CVE-2022-32212
A OS Command Injection vulnerability exists in Node.js versions <14.20.0 <16.20.0 <18.5.0 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding attacks.
CVE-2022-32212
A OS Command Injection vulnerability exists in Node.js versions <14.20 ...
GHSA-w95h-2gj2-x2p4
A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding attacks.
SUSE-SU-2022:2551-1
Security update for nodejs16
SUSE-SU-2022:2491-1
Security update for nodejs16
SUSE-SU-2022:2430-1
Security update for nodejs12
SUSE-SU-2022:2425-1
Security update for nodejs14
SUSE-SU-2022:2416-1
Security update for nodejs14
SUSE-SU-2022:2415-1
Security update for nodejs16
SUSE-SU-2022:2417-1
Security update for nodejs12
RLSA-2022:6448
Moderate: nodejs:14 security and bug fix update
ELSA-2022-6448
ELSA-2022-6448: nodejs:14 security and bug fix update (MODERATE)
RLSA-2022:6449
Moderate: nodejs:16 security and bug fix update
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2024-07321 Уязвимость функции IsIPAddress() программной платформы Node.js, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании | CVSS3: 8.1 | 6% Низкий | около 4 лет назад | |
ALT-PU-2022-2701 ALT-PU-2022-2701: package `node` update to version 16.17.1-alt1 | CVSS3: 9.8 | почти 4 года назад | ||
ALT-PU-2022-3235 ALT-PU-2022-3235: package `node` update to version 14.21.1-alt1 | CVSS3: 9.8 | почти 4 года назад | ||
ALT-PU-2023-1461 ALT-PU-2023-1461: package `node` update to version 16.18.1-alt1 | CVSS3: 9.8 | больше 3 лет назад | ||
CVE-2022-32212 A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding attacks. | CVSS3: 8.1 | 6% Низкий | около 4 лет назад | |
CVE-2022-32212 A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding attacks. | CVSS3: 7.5 | 6% Низкий | около 4 лет назад | |
CVE-2022-32212 A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding attacks. | CVSS3: 8.1 | 6% Низкий | около 4 лет назад | |
CVE-2022-32212 A OS Command Injection vulnerability exists in Node.js versions <14.20.0 <16.20.0 <18.5.0 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding attacks. | CVSS3: 8.1 | 6% Низкий | около 4 лет назад | |
CVE-2022-32212 A OS Command Injection vulnerability exists in Node.js versions <14.20 ... | CVSS3: 8.1 | 6% Низкий | около 4 лет назад | |
GHSA-w95h-2gj2-x2p4 A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding attacks. | CVSS3: 8.1 | 6% Низкий | около 4 лет назад | |
SUSE-SU-2022:2551-1 Security update for nodejs16 | около 4 лет назад | |||
SUSE-SU-2022:2491-1 Security update for nodejs16 | около 4 лет назад | |||
SUSE-SU-2022:2430-1 Security update for nodejs12 | около 4 лет назад | |||
SUSE-SU-2022:2425-1 Security update for nodejs14 | около 4 лет назад | |||
SUSE-SU-2022:2416-1 Security update for nodejs14 | около 4 лет назад | |||
SUSE-SU-2022:2415-1 Security update for nodejs16 | около 4 лет назад | |||
SUSE-SU-2022:2417-1 Security update for nodejs12 | около 4 лет назад | |||
RLSA-2022:6448 Moderate: nodejs:14 security and bug fix update | около 4 лет назад | |||
ELSA-2022-6448 ELSA-2022-6448: nodejs:14 security and bug fix update (MODERATE) | около 4 лет назад | |||
RLSA-2022:6449 Moderate: nodejs:16 security and bug fix update | около 4 лет назад |
Уязвимостей на страницу