Количество 24
Количество 24
ELSA-2024-6148
ELSA-2024-6148: nodejs:18 security update (MODERATE)
ELSA-2024-6147
ELSA-2024-6147: nodejs:18 security update (MODERATE)
ELSA-2024-5814
ELSA-2024-5814: nodejs:20 security update (MODERATE)

CVE-2024-28863
node-tar is a Tar for Node.js. node-tar prior to version 6.2.1 has no limit on the number of sub-folders created in the folder creation process. An attacker who generates a large number of sub-folders can consume memory on the system running node-tar and even crash the Node.js client within few seconds of running it using a path with too many sub-folders inside. Version 6.2.1 fixes this issue by preventing extraction in excessively deep sub-folders.

CVE-2024-28863
node-tar is a Tar for Node.js. node-tar prior to version 6.2.1 has no limit on the number of sub-folders created in the folder creation process. An attacker who generates a large number of sub-folders can consume memory on the system running node-tar and even crash the Node.js client within few seconds of running it using a path with too many sub-folders inside. Version 6.2.1 fixes this issue by preventing extraction in excessively deep sub-folders.

CVE-2024-28863
node-tar is a Tar for Node.js. node-tar prior to version 6.2.1 has no limit on the number of sub-folders created in the folder creation process. An attacker who generates a large number of sub-folders can consume memory on the system running node-tar and even crash the Node.js client within few seconds of running it using a path with too many sub-folders inside. Version 6.2.1 fixes this issue by preventing extraction in excessively deep sub-folders.

CVE-2024-28863
CVE-2024-28863
node-tar is a Tar for Node.js. node-tar prior to version 6.2.1 has no ...

CVE-2024-22020
A security flaw in Node.js allows a bypass of network import restrictions. By embedding non-network imports in data URLs, an attacker can execute arbitrary code, compromising system security. Verified on various platforms, the vulnerability is mitigated by forbidding data URLs in network imports. Exploiting this flaw can violate network import security, posing a risk to developers and servers.

CVE-2024-22020
A security flaw in Node.js allows a bypass of network import restrictions. By embedding non-network imports in data URLs, an attacker can execute arbitrary code, compromising system security. Verified on various platforms, the vulnerability is mitigated by forbidding data URLs in network imports. Exploiting this flaw can violate network import security, posing a risk to developers and servers.

CVE-2024-22020
A security flaw in Node.js allows a bypass of network import restrictions. By embedding non-network imports in data URLs, an attacker can execute arbitrary code, compromising system security. Verified on various platforms, the vulnerability is mitigated by forbidding data URLs in network imports. Exploiting this flaw can violate network import security, posing a risk to developers and servers.

CVE-2024-22020
CVE-2024-22020
A security flaw in Node.js allows a bypass of network import restrict ...
GHSA-f5x3-32g6-xq36
Denial of service while parsing a tar file due to lack of folders count validation

BDU:2024-09418
Уязвимость модуля node-tar библиотеки Node.js, позволяющая нарушителю вызвать отказ в обслуживании

ROS-20240904-05
Уязвимость nodejs
GHSA-ch4x-f5c4-36gv
A security flaw in Node.js allows a bypass of network import restrictions. By embedding non-network imports in data URLs, an attacker can execute arbitrary code, compromising system security. Verified on various platforms, the vulnerability is mitigated by forbidding data URLs in network imports. Exploiting this flaw can violate network import security, posing a risk to developers and servers.

BDU:2024-06867
Уязвимость программной платформы Node.js, связанная с неправильным контролем доступа, позволяющая нарушителю выполнить произвольный код

SUSE-SU-2024:2542-1
Security update for nodejs18

SUSE-SU-2024:2496-1
Security update for nodejs18
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
ELSA-2024-6148 ELSA-2024-6148: nodejs:18 security update (MODERATE) | 10 месяцев назад | |||
ELSA-2024-6147 ELSA-2024-6147: nodejs:18 security update (MODERATE) | 10 месяцев назад | |||
ELSA-2024-5814 ELSA-2024-5814: nodejs:20 security update (MODERATE) | 10 месяцев назад | |||
![]() | CVE-2024-28863 node-tar is a Tar for Node.js. node-tar prior to version 6.2.1 has no limit on the number of sub-folders created in the folder creation process. An attacker who generates a large number of sub-folders can consume memory on the system running node-tar and even crash the Node.js client within few seconds of running it using a path with too many sub-folders inside. Version 6.2.1 fixes this issue by preventing extraction in excessively deep sub-folders. | CVSS3: 6.5 | 0% Низкий | около 1 года назад |
![]() | CVE-2024-28863 node-tar is a Tar for Node.js. node-tar prior to version 6.2.1 has no limit on the number of sub-folders created in the folder creation process. An attacker who generates a large number of sub-folders can consume memory on the system running node-tar and even crash the Node.js client within few seconds of running it using a path with too many sub-folders inside. Version 6.2.1 fixes this issue by preventing extraction in excessively deep sub-folders. | CVSS3: 6.5 | 0% Низкий | около 1 года назад |
![]() | CVE-2024-28863 node-tar is a Tar for Node.js. node-tar prior to version 6.2.1 has no limit on the number of sub-folders created in the folder creation process. An attacker who generates a large number of sub-folders can consume memory on the system running node-tar and even crash the Node.js client within few seconds of running it using a path with too many sub-folders inside. Version 6.2.1 fixes this issue by preventing extraction in excessively deep sub-folders. | CVSS3: 6.5 | 0% Низкий | около 1 года назад |
![]() | CVSS3: 6.5 | 0% Низкий | 12 месяцев назад | |
CVE-2024-28863 node-tar is a Tar for Node.js. node-tar prior to version 6.2.1 has no ... | CVSS3: 6.5 | 0% Низкий | около 1 года назад | |
![]() | CVE-2024-22020 A security flaw in Node.js allows a bypass of network import restrictions. By embedding non-network imports in data URLs, an attacker can execute arbitrary code, compromising system security. Verified on various platforms, the vulnerability is mitigated by forbidding data URLs in network imports. Exploiting this flaw can violate network import security, posing a risk to developers and servers. | CVSS3: 6.5 | 0% Низкий | 12 месяцев назад |
![]() | CVE-2024-22020 A security flaw in Node.js allows a bypass of network import restrictions. By embedding non-network imports in data URLs, an attacker can execute arbitrary code, compromising system security. Verified on various platforms, the vulnerability is mitigated by forbidding data URLs in network imports. Exploiting this flaw can violate network import security, posing a risk to developers and servers. | CVSS3: 6.5 | 0% Низкий | 12 месяцев назад |
![]() | CVE-2024-22020 A security flaw in Node.js allows a bypass of network import restrictions. By embedding non-network imports in data URLs, an attacker can execute arbitrary code, compromising system security. Verified on various platforms, the vulnerability is mitigated by forbidding data URLs in network imports. Exploiting this flaw can violate network import security, posing a risk to developers and servers. | CVSS3: 6.5 | 0% Низкий | 12 месяцев назад |
![]() | CVSS3: 6.5 | 0% Низкий | 4 месяца назад | |
CVE-2024-22020 A security flaw in Node.js allows a bypass of network import restrict ... | CVSS3: 6.5 | 0% Низкий | 12 месяцев назад | |
GHSA-f5x3-32g6-xq36 Denial of service while parsing a tar file due to lack of folders count validation | CVSS3: 6.5 | 0% Низкий | около 1 года назад | |
![]() | BDU:2024-09418 Уязвимость модуля node-tar библиотеки Node.js, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 6.5 | 0% Низкий | около 1 года назад |
![]() | ROS-20240904-05 Уязвимость nodejs | CVSS3: 6.5 | 0% Низкий | 10 месяцев назад |
GHSA-ch4x-f5c4-36gv A security flaw in Node.js allows a bypass of network import restrictions. By embedding non-network imports in data URLs, an attacker can execute arbitrary code, compromising system security. Verified on various platforms, the vulnerability is mitigated by forbidding data URLs in network imports. Exploiting this flaw can violate network import security, posing a risk to developers and servers. | CVSS3: 6.5 | 0% Низкий | 12 месяцев назад | |
![]() | BDU:2024-06867 Уязвимость программной платформы Node.js, связанная с неправильным контролем доступа, позволяющая нарушителю выполнить произвольный код | CVSS3: 6.5 | 0% Низкий | 12 месяцев назад |
![]() | SUSE-SU-2024:2542-1 Security update for nodejs18 | 11 месяцев назад | ||
![]() | SUSE-SU-2024:2496-1 Security update for nodejs18 | 11 месяцев назад |
Уязвимостей на страницу