VYPR

apk package

chainguard/nodejs-22

pkg:apk/chainguard/nodejs-22

Vulnerabilities (22)

  • CVE-2024-22018LowJul 10, 2024
    affected < 22.4.1-r0fixed 22.4.1-r0

    A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-read flag is used. This flaw arises from an inadequate permission model that fails to restrict file stats through the fs.lstat API. As a result, malicious acto

  • CVE-2024-22020MedJul 9, 2024
    affected < 22.4.1-r0fixed 22.4.1-r0

    A security flaw in Node.js allows a bypass of network import restrictions. By embedding non-network imports in data URLs, an attacker can execute arbitrary code, compromising system security. Verified on various platforms, the vulnerability is mitigated by forbidding data URLs i

Page 2 of 2