rpm package
almalinux/nodejs-packaging-bundler
pkg:rpm/almalinux/nodejs-packaging-bundler
Vulnerabilities (104)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2022-43548 | Hig | 8.1 | < 2021.06-4.module_el9.1.0+13+d9a595ea | 2021.06-4.module_el9.1.0+13+d9a595ea | Dec 5, 2022 | A OS Command Injection vulnerability exists in Node.js versions <14.21.1, <16.18.1, <18.12.1, <19.0.1 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing | |
| CVE-2022-35256 | Med | 6.5 | < 2021.06-4.module_el8.7.0+3343+ea2b7901 | 2021.06-4.module_el8.7.0+3343+ea2b7901 | Dec 5, 2022 | The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling. | |
| CVE-2022-35255 | Cri | 9.1 | < 2021.06-4.module_el8.7.0+3343+ea2b7901 | 2021.06-4.module_el8.7.0+3343+ea2b7901 | Dec 5, 2022 | A weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with EntropySource() in SecretKeyGenTraits::DoKeyGen() in src/crypto/crypto_keygen.cc. There are two problems with this: 1) It does not check the return value, it assumes EntropySource() alwa | |
| CVE-2022-3517 | Hig | 7.5 | < 2021.06-4.module_el9.1.0+13+d9a595ea | 2021.06-4.module_el9.1.0+13+d9a595ea | Oct 17, 2022 | A vulnerability was found in the minimatch package. This flaw allows a Regular Expression Denial of Service (ReDoS) when calling the braceExpand function with specific arguments, resulting in a Denial of Service. |
- affected < 2021.06-4.module_el9.1.0+13+d9a595eafixed 2021.06-4.module_el9.1.0+13+d9a595ea
A OS Command Injection vulnerability exists in Node.js versions <14.21.1, <16.18.1, <18.12.1, <19.0.1 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing
- affected < 2021.06-4.module_el8.7.0+3343+ea2b7901fixed 2021.06-4.module_el8.7.0+3343+ea2b7901
The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling.
- affected < 2021.06-4.module_el8.7.0+3343+ea2b7901fixed 2021.06-4.module_el8.7.0+3343+ea2b7901
A weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with EntropySource() in SecretKeyGenTraits::DoKeyGen() in src/crypto/crypto_keygen.cc. There are two problems with this: 1) It does not check the return value, it assumes EntropySource() alwa
- affected < 2021.06-4.module_el9.1.0+13+d9a595eafixed 2021.06-4.module_el9.1.0+13+d9a595ea
A vulnerability was found in the minimatch package. This flaw allows a Regular Expression Denial of Service (ReDoS) when calling the braceExpand function with specific arguments, resulting in a Denial of Service.
Page 6 of 6