VYPR

apk package

wolfi/nodejs-16-doc

pkg:apk/wolfi/nodejs-16-doc

Vulnerabilities (27)

  • CVE-2023-39331HigOct 18, 2023
    affected < 0fixed 0

    A previously disclosed vulnerability (CVE-2023-30584) was patched insufficiently in commit 205f1e6. The new path traversal vulnerability arises because the implementation does not protect itself against the application overwriting built-in utility functions with user-defined impl

  • CVE-2023-32559HigAug 24, 2023
    affected < 16.20.2-r0fixed 16.20.2-r0

    A privilege escalation vulnerability exists in the experimental policy mechanism in all active release lines: 16.x, 18.x and, 20.x. The use of the deprecated API `process.binding()` can bypass the policy mechanism by requiring internal modules and eventually take advantage of `pr

  • CVE-2023-32002CriAug 21, 2023
    affected < 16.20.2-r0fixed 16.20.2-r0

    The use of `Module._load()` can bypass the policy mechanism and require modules outside of the policy.json definition for a given module. This vulnerability affects all users using the experimental policy mechanism in all active release lines: 16.x, 18.x and, 20.x. Please note

  • CVE-2023-32006HigAug 15, 2023
    affected < 16.20.2-r0fixed 16.20.2-r0

    The use of `module.constructor.createRequire()` can bypass the policy mechanism and require modules outside of the policy.json definition for a given module. This vulnerability affects all users using the experimental policy mechanism in all active release lines: 16.x, 18.x, and

  • CVE-2023-32004HigAug 15, 2023
    affected < 0fixed 0

    A vulnerability has been discovered in Node.js version 20, specifically within the experimental permission model. This flaw relates to improper handling of Buffers in file system APIs causing a traversal path to bypass when verifying file permissions. This vulnerability affects

  • CVE-2023-32003MedAug 15, 2023
    affected < 0fixed 0

    `fs.mkdtemp()` and `fs.mkdtempSync()` can be used to bypass the permission model check using a path traversal attack. This flaw arises from a missing check in the fs.mkdtemp() API and the impact is a malicious actor could create an arbitrary directory. This vulnerability affects

  • CVE-2023-30589HigJul 1, 2023
    affected < 16.20.1-r0fixed 16.20.1-r0

    The llhttp parser in the http module in Node v20.2.0 does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS). The CR character (without LF) is sufficient to delimit HTTP header fields in the llhttp parser. According to RF

Page 2 of 2