VYPR

rpm package

almalinux/nodejs-libs

pkg:rpm/almalinux/nodejs-libs

Vulnerabilities (97)

  • CVE-2023-23936MedFeb 16, 2023
    affected < 1:16.19.1-1.el9_2fixed 1:16.19.1-1.el9_2

    Undici is an HTTP/1.1 client for Node.js. Starting with version 2.0.0 and prior to version 5.19.1, the undici library does not protect `host` HTTP header from CRLF injection vulnerabilities. This issue is patched in Undici v5.19.1. As a workaround, sanitize the `headers.host` str

  • CVE-2022-25881MedJan 31, 2023
    affected < 1:16.19.1-1.el9_2fixed 1:16.19.1-1.el9_2

    This affects versions of the package http-cache-semantics before 4.1.1. The issue can be exploited via malicious request header values sent to a server, when that server reads the cache policy from the request using this library.

  • CVE-2022-43548HigDec 5, 2022
    affected < 1:16.18.1-3.el9_1fixed 1:16.18.1-3.el9_1

    A OS Command Injection vulnerability exists in Node.js versions <14.21.1, <16.18.1, <18.12.1, <19.0.1 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing

  • CVE-2022-35256MedDec 5, 2022
    affected < 1:16.17.1-1.el9_0fixed 1:16.17.1-1.el9_0

    The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling.

  • CVE-2022-35255CriDec 5, 2022
    affected < 1:16.17.1-1.el9_0fixed 1:16.17.1-1.el9_0

    A weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with EntropySource() in SecretKeyGenTraits::DoKeyGen() in src/crypto/crypto_keygen.cc. There are two problems with this: 1) It does not check the return value, it assumes EntropySource() alwa

  • CVE-2022-3517HigOct 17, 2022
    affected < 1:16.18.1-3.el9_1fixed 1:16.18.1-3.el9_1

    A vulnerability was found in the minimatch package. This flaw allows a Regular Expression Denial of Service (ReDoS) when calling the braceExpand function with specific arguments, resulting in a Denial of Service.

  • CVE-2022-32215MedJul 14, 2022
    affected < 1:16.16.0-1.el9_0fixed 1:16.16.0-1.el9_0

    The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding headers. This can lead to HTTP Request Smuggling (HRS).

  • CVE-2022-32214MedJul 14, 2022
    affected < 1:16.16.0-1.el9_0fixed 1:16.16.0-1.el9_0

    The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS).

  • CVE-2022-32213MedJul 14, 2022
    affected < 1:16.16.0-1.el9_0fixed 1:16.16.0-1.el9_0

    The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS).

  • CVE-2022-32212HigJul 14, 2022
    affected < 1:16.16.0-1.el9_0fixed 1:16.16.0-1.el9_0

    A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding

  • CVE-2022-33987MedJun 18, 2022
    affected < 1:16.16.0-1.el9_0fixed 1:16.16.0-1.el9_0

    The got package before 12.1.0 (also fixed in 11.8.5) for Node.js allows a redirect to a UNIX socket.

  • CVE-2022-29244HigJun 13, 2022
    affected < 1:16.16.0-1.el9_0fixed 1:16.16.0-1.el9_0

    npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace or with a workspace flag (ie. `--workspaces`, `--workspace=`). Anyone who has run `npm pack` or `npm publish` inside a workspace, as of v7.9.0 and v7.13.0 respectively, m

  • CVE-2021-44906CriMar 17, 2022
    affected < 1:16.18.1-3.el9_1fixed 1:16.18.1-3.el9_1

    Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95).

  • CVE-2021-3807HigSep 17, 2021
    affected < 1:16.16.0-1.el9_0fixed 1:16.16.0-1.el9_0

    ansi-regex is vulnerable to Inefficient Regular Expression Complexity

  • CVE-2020-28469MedJun 3, 2021
    affected < 1:16.16.0-1.el9_0fixed 1:16.16.0-1.el9_0

    This affects the package glob-parent before 5.1.2. The enclosure regex used to check for strings ending in enclosure containing path separator.

  • CVE-2021-33502HigMay 24, 2021
    affected < 1:16.16.0-1.el9_0fixed 1:16.16.0-1.el9_0

    The normalize-url package before 4.5.1, 5.x before 5.3.1, and 6.x before 6.0.1 for Node.js has a ReDoS (regular expression denial of service) issue because it has exponential performance for data: URLs.

  • CVE-2020-7788HigDec 11, 2020
    affected < 1:16.16.0-1.el9_0fixed 1:16.16.0-1.el9_0

    This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be exploited further depending on the context.

Page 5 of 5