rpm package
almalinux/nodejs-libs
pkg:rpm/almalinux/nodejs-libs
Vulnerabilities (97)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2023-23936 | Med | 6.5 | < 1:16.19.1-1.el9_2 | 1:16.19.1-1.el9_2 | Feb 16, 2023 | Undici is an HTTP/1.1 client for Node.js. Starting with version 2.0.0 and prior to version 5.19.1, the undici library does not protect `host` HTTP header from CRLF injection vulnerabilities. This issue is patched in Undici v5.19.1. As a workaround, sanitize the `headers.host` str | |
| CVE-2022-25881 | Med | 5.3 | < 1:16.19.1-1.el9_2 | 1:16.19.1-1.el9_2 | Jan 31, 2023 | This affects versions of the package http-cache-semantics before 4.1.1. The issue can be exploited via malicious request header values sent to a server, when that server reads the cache policy from the request using this library. | |
| CVE-2022-43548 | Hig | 8.1 | < 1:16.18.1-3.el9_1 | 1:16.18.1-3.el9_1 | Dec 5, 2022 | A OS Command Injection vulnerability exists in Node.js versions <14.21.1, <16.18.1, <18.12.1, <19.0.1 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing | |
| CVE-2022-35256 | Med | 6.5 | < 1:16.17.1-1.el9_0 | 1:16.17.1-1.el9_0 | Dec 5, 2022 | The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling. | |
| CVE-2022-35255 | Cri | 9.1 | < 1:16.17.1-1.el9_0 | 1:16.17.1-1.el9_0 | Dec 5, 2022 | A weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with EntropySource() in SecretKeyGenTraits::DoKeyGen() in src/crypto/crypto_keygen.cc. There are two problems with this: 1) It does not check the return value, it assumes EntropySource() alwa | |
| CVE-2022-3517 | Hig | 7.5 | < 1:16.18.1-3.el9_1 | 1:16.18.1-3.el9_1 | Oct 17, 2022 | A vulnerability was found in the minimatch package. This flaw allows a Regular Expression Denial of Service (ReDoS) when calling the braceExpand function with specific arguments, resulting in a Denial of Service. | |
| CVE-2022-32215 | Med | 6.5 | < 1:16.16.0-1.el9_0 | 1:16.16.0-1.el9_0 | Jul 14, 2022 | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding headers. This can lead to HTTP Request Smuggling (HRS). | |
| CVE-2022-32214 | Med | 6.5 | < 1:16.16.0-1.el9_0 | 1:16.16.0-1.el9_0 | Jul 14, 2022 | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS). | |
| CVE-2022-32213 | Med | 6.5 | < 1:16.16.0-1.el9_0 | 1:16.16.0-1.el9_0 | Jul 14, 2022 | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS). | |
| CVE-2022-32212 | Hig | 8.1 | < 1:16.16.0-1.el9_0 | 1:16.16.0-1.el9_0 | Jul 14, 2022 | A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding | |
| CVE-2022-33987 | Med | 5.3 | < 1:16.16.0-1.el9_0 | 1:16.16.0-1.el9_0 | Jun 18, 2022 | The got package before 12.1.0 (also fixed in 11.8.5) for Node.js allows a redirect to a UNIX socket. | |
| CVE-2022-29244 | Hig | 7.5 | < 1:16.16.0-1.el9_0 | 1:16.16.0-1.el9_0 | Jun 13, 2022 | npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace or with a workspace flag (ie. `--workspaces`, `--workspace=`). Anyone who has run `npm pack` or `npm publish` inside a workspace, as of v7.9.0 and v7.13.0 respectively, m | |
| CVE-2021-44906 | Cri | 9.8 | < 1:16.18.1-3.el9_1 | 1:16.18.1-3.el9_1 | Mar 17, 2022 | Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95). | |
| CVE-2021-3807 | Hig | 7.5 | < 1:16.16.0-1.el9_0 | 1:16.16.0-1.el9_0 | Sep 17, 2021 | ansi-regex is vulnerable to Inefficient Regular Expression Complexity | |
| CVE-2020-28469 | Med | 5.3 | < 1:16.16.0-1.el9_0 | 1:16.16.0-1.el9_0 | Jun 3, 2021 | This affects the package glob-parent before 5.1.2. The enclosure regex used to check for strings ending in enclosure containing path separator. | |
| CVE-2021-33502 | Hig | 7.5 | < 1:16.16.0-1.el9_0 | 1:16.16.0-1.el9_0 | May 24, 2021 | The normalize-url package before 4.5.1, 5.x before 5.3.1, and 6.x before 6.0.1 for Node.js has a ReDoS (regular expression denial of service) issue because it has exponential performance for data: URLs. | |
| CVE-2020-7788 | Hig | 7.3 | < 1:16.16.0-1.el9_0 | 1:16.16.0-1.el9_0 | Dec 11, 2020 | This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be exploited further depending on the context. |
- affected < 1:16.19.1-1.el9_2fixed 1:16.19.1-1.el9_2
Undici is an HTTP/1.1 client for Node.js. Starting with version 2.0.0 and prior to version 5.19.1, the undici library does not protect `host` HTTP header from CRLF injection vulnerabilities. This issue is patched in Undici v5.19.1. As a workaround, sanitize the `headers.host` str
- affected < 1:16.19.1-1.el9_2fixed 1:16.19.1-1.el9_2
This affects versions of the package http-cache-semantics before 4.1.1. The issue can be exploited via malicious request header values sent to a server, when that server reads the cache policy from the request using this library.
- affected < 1:16.18.1-3.el9_1fixed 1:16.18.1-3.el9_1
A OS Command Injection vulnerability exists in Node.js versions <14.21.1, <16.18.1, <18.12.1, <19.0.1 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing
- affected < 1:16.17.1-1.el9_0fixed 1:16.17.1-1.el9_0
The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling.
- affected < 1:16.17.1-1.el9_0fixed 1:16.17.1-1.el9_0
A weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with EntropySource() in SecretKeyGenTraits::DoKeyGen() in src/crypto/crypto_keygen.cc. There are two problems with this: 1) It does not check the return value, it assumes EntropySource() alwa
- affected < 1:16.18.1-3.el9_1fixed 1:16.18.1-3.el9_1
A vulnerability was found in the minimatch package. This flaw allows a Regular Expression Denial of Service (ReDoS) when calling the braceExpand function with specific arguments, resulting in a Denial of Service.
- affected < 1:16.16.0-1.el9_0fixed 1:16.16.0-1.el9_0
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding headers. This can lead to HTTP Request Smuggling (HRS).
- affected < 1:16.16.0-1.el9_0fixed 1:16.16.0-1.el9_0
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS).
- affected < 1:16.16.0-1.el9_0fixed 1:16.16.0-1.el9_0
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS).
- affected < 1:16.16.0-1.el9_0fixed 1:16.16.0-1.el9_0
A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding
- affected < 1:16.16.0-1.el9_0fixed 1:16.16.0-1.el9_0
The got package before 12.1.0 (also fixed in 11.8.5) for Node.js allows a redirect to a UNIX socket.
- affected < 1:16.16.0-1.el9_0fixed 1:16.16.0-1.el9_0
npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace or with a workspace flag (ie. `--workspaces`, `--workspace=`). Anyone who has run `npm pack` or `npm publish` inside a workspace, as of v7.9.0 and v7.13.0 respectively, m
- affected < 1:16.18.1-3.el9_1fixed 1:16.18.1-3.el9_1
Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95).
- affected < 1:16.16.0-1.el9_0fixed 1:16.16.0-1.el9_0
ansi-regex is vulnerable to Inefficient Regular Expression Complexity
- affected < 1:16.16.0-1.el9_0fixed 1:16.16.0-1.el9_0
This affects the package glob-parent before 5.1.2. The enclosure regex used to check for strings ending in enclosure containing path separator.
- affected < 1:16.16.0-1.el9_0fixed 1:16.16.0-1.el9_0
The normalize-url package before 4.5.1, 5.x before 5.3.1, and 6.x before 6.0.1 for Node.js has a ReDoS (regular expression denial of service) issue because it has exponential performance for data: URLs.
- affected < 1:16.16.0-1.el9_0fixed 1:16.16.0-1.el9_0
This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be exploited further depending on the context.
Page 5 of 5