VYPR

apk package

wolfi/nodejs-18

pkg:apk/wolfi/nodejs-18

Vulnerabilities (23)

  • CVE-2023-32004HigAug 15, 2023
    affected < 0fixed 0

    A vulnerability has been discovered in Node.js version 20, specifically within the experimental permission model. This flaw relates to improper handling of Buffers in file system APIs causing a traversal path to bypass when verifying file permissions. This vulnerability affects

  • CVE-2023-32003MedAug 15, 2023
    affected < 0fixed 0

    `fs.mkdtemp()` and `fs.mkdtempSync()` can be used to bypass the permission model check using a path traversal attack. This flaw arises from a missing check in the fs.mkdtemp() API and the impact is a malicious actor could create an arbitrary directory. This vulnerability affects

  • CVE-2023-30589HigJul 1, 2023
    affected < 18.16.1-r0fixed 18.16.1-r0

    The llhttp parser in the http module in Node v20.2.0 does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS). The CR character (without LF) is sufficient to delimit HTTP header fields in the llhttp parser. According to RF

Page 2 of 2