VYPR

rpm package

almalinux/nodejs-libs

pkg:rpm/almalinux/nodejs-libs

Vulnerabilities (97)

  • CVE-2024-28182MedApr 4, 2024
    affected < 1:16.20.2-8.el9_4fixed 1:16.20.2-8.el9_4

    nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. The nghttp2 library prior to version 1.61.0 keeps reading the unbounded number of HTTP/2 CONTINUATION frames even after a stream is reset to keep HPACK context in sync. This causes excessive CPU usag

  • CVE-2024-22025MedMar 19, 2024
    affected < 1:16.20.2-8.el9_4fixed 1:16.20.2-8.el9_4

    A vulnerability in Node.js has been identified, allowing for a Denial of Service (DoS) attack through resource exhaustion when using the fetch() function to retrieve content from an untrusted URL. The vulnerability stems from the fact that the fetch() function in Node.js always d

  • CVE-2024-25629MedFeb 23, 2024
    affected < 1:16.20.2-8.el9_4fixed 1:16.20.2-8.el9_4

    c-ares is a C library for asynchronous DNS requests. `ares__read_line()` is used to parse local configuration files such as `/etc/resolv.conf`, `/etc/nsswitch.conf`, the `HOSTALIASES` file, and if using a c-ares version prior to 1.27.0, the `/etc/hosts` file. If any of these conf

  • CVE-2024-22019HigFeb 20, 2024
    affected < 1:16.20.2-4.el9_3fixed 1:16.20.2-4.el9_3

    A vulnerability in Node.js HTTP servers allows an attacker to send a specially crafted HTTP request with chunked encoding, leading to resource exhaustion and denial of service (DoS). The server reads an unbounded number of bytes from a single connection, exploiting the lack of li

  • CVE-2023-30590HigNov 28, 2023
    affected < 1:16.20.1-1.el9_2fixed 1:16.20.1-1.el9_2

    The generateKeys() API function returned from crypto.createDiffieHellman() only generates missing (or outdated) keys, that is, it only generates a private key if none has been set yet, but the function is also needed to compute the corresponding public key after calling setPrivat

  • CVE-2023-30588MedNov 28, 2023
    affected < 1:16.20.1-1.el9_2fixed 1:16.20.1-1.el9_2

    When an invalid public key is used to create an x509 certificate using the crypto.X509Certificate() API a non-expect termination occurs making it susceptible to DoS attacks when the attacker could force interruptions of application processing, as the process terminates when acces

  • CVE-2023-30581HigNov 23, 2023
    affected < 1:16.20.1-1.el9_2fixed 1:16.20.1-1.el9_2

    The use of __proto__ in process.mainModule.__proto__.require() can bypass the policy mechanism and require modules outside of the policy.json definition. This vulnerability affects all users using the experimental policy mechanism in all active release lines: v16, v18 and, v20.

  • CVE-2023-44487HigKEVOct 10, 2023
    affected < 1:16.20.2-3.el9_2fixed 1:16.20.2-3.el9_2

    The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

  • CVE-2023-32559HigAug 24, 2023
    affected < 1:16.20.2-1.el9_2fixed 1:16.20.2-1.el9_2

    A privilege escalation vulnerability exists in the experimental policy mechanism in all active release lines: 16.x, 18.x and, 20.x. The use of the deprecated API `process.binding()` can bypass the policy mechanism by requiring internal modules and eventually take advantage of `pr

  • CVE-2023-32002CriAug 21, 2023
    affected < 1:16.20.2-1.el9_2fixed 1:16.20.2-1.el9_2

    The use of `Module._load()` can bypass the policy mechanism and require modules outside of the policy.json definition for a given module. This vulnerability affects all users using the experimental policy mechanism in all active release lines: 16.x, 18.x and, 20.x. Please note

  • CVE-2023-32006HigAug 15, 2023
    affected < 1:16.20.2-1.el9_2fixed 1:16.20.2-1.el9_2

    The use of `module.constructor.createRequire()` can bypass the policy mechanism and require modules outside of the policy.json definition for a given module. This vulnerability affects all users using the experimental policy mechanism in all active release lines: 16.x, 18.x, and

  • CVE-2023-30589HigJul 1, 2023
    affected < 1:16.20.1-1.el9_2fixed 1:16.20.1-1.el9_2

    The llhttp parser in the http module in Node v20.2.0 does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS). The CR character (without LF) is sufficient to delimit HTTP header fields in the llhttp parser. According to RF

  • CVE-2023-32067HigMay 25, 2023
    affected < 1:16.19.1-2.el9_2fixed 1:16.19.1-2.el9_2

    c-ares is an asynchronous resolver library. c-ares is vulnerable to denial of service. If a target resolver sends a query, the attacker forges a malformed UDP packet with a length of 0 and returns them to the target resolver. The target resolver erroneously interprets the 0 lengt

  • CVE-2023-31147MedMay 25, 2023
    affected < 1:16.19.1-2.el9_2fixed 1:16.19.1-2.el9_2

    c-ares is an asynchronous resolver library. When /dev/urandom or RtlGenRandom() are unavailable, c-ares uses rand() to generate random numbers used for DNS query ids. This is not a CSPRNG, and it is also not seeded by srand() so will generate predictable output. Input from the ra

  • CVE-2023-31130MedMay 25, 2023
    affected < 1:16.19.1-2.el9_2fixed 1:16.19.1-2.el9_2

    c-ares is an asynchronous resolver library. ares_inet_net_pton() is vulnerable to a buffer underflow for certain ipv6 addresses, in particular "0::00:00:00/2" was found to cause an issue. C-ares only uses this function internally for configuration purposes which would require an

  • CVE-2023-31124LowMay 25, 2023
    affected < 1:16.19.1-2.el9_2fixed 1:16.19.1-2.el9_2

    c-ares is an asynchronous resolver library. When cross-compiling c-ares and using the autotools build system, CARES_RANDOM_FILE will not be set, as seen when cross compiling aarch64 android. This will downgrade to using rand() as a fallback which could allow an attacker to take

  • CVE-2022-4904HigMar 6, 2023
    affected < 1:16.19.1-1.el9_2fixed 1:16.19.1-1.el9_2

    A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbitrary length stack overflow. This issue may cause a denial of service or a limited impact on confidentiality and integrity.

  • CVE-2023-23920MedFeb 23, 2023
    affected < 1:16.19.1-1.el9_2fixed 1:16.19.1-1.el9_2

    An untrusted search path vulnerability exists in Node.js. <19.6.1, <18.14.1, <16.19.1, and <14.21.3 that could allow an attacker to search and potentially load ICU data when running with elevated privileges.

  • CVE-2023-23918HigFeb 23, 2023
    affected < 1:16.19.1-1.el9_2fixed 1:16.19.1-1.el9_2

    A privilege escalation vulnerability exists in Node.js <19.6.1, <18.14.1, <16.19.1 and <14.21.3 that made it possible to bypass the experimental Permissions (https://nodejs.org/api/permissions.html) feature in Node.js and access non authorized modules by using process.mainModule.

  • CVE-2023-24807HigFeb 16, 2023
    affected < 1:16.19.1-1.el9_2fixed 1:16.19.1-1.el9_2

    Undici is an HTTP/1.1 client for Node.js. Prior to version 5.19.1, the `Headers.set()` and `Headers.append()` methods are vulnerable to Regular Expression Denial of Service (ReDoS) attacks when untrusted values are passed into the functions. This is due to the inefficient regular

Page 4 of 5