VYPR

rpm package

almalinux/nodejs-packaging-bundler

pkg:rpm/almalinux/nodejs-packaging-bundler

Vulnerabilities (104)

  • CVE-2022-43548HigDec 5, 2022
    affected < 2021.06-4.module_el9.1.0+13+d9a595eafixed 2021.06-4.module_el9.1.0+13+d9a595ea

    A OS Command Injection vulnerability exists in Node.js versions <14.21.1, <16.18.1, <18.12.1, <19.0.1 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing

  • CVE-2022-35256MedDec 5, 2022
    affected < 2021.06-4.module_el8.7.0+3343+ea2b7901fixed 2021.06-4.module_el8.7.0+3343+ea2b7901

    The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling.

  • CVE-2022-35255CriDec 5, 2022
    affected < 2021.06-4.module_el8.7.0+3343+ea2b7901fixed 2021.06-4.module_el8.7.0+3343+ea2b7901

    A weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with EntropySource() in SecretKeyGenTraits::DoKeyGen() in src/crypto/crypto_keygen.cc. There are two problems with this: 1) It does not check the return value, it assumes EntropySource() alwa

  • CVE-2022-3517HigOct 17, 2022
    affected < 2021.06-4.module_el9.1.0+13+d9a595eafixed 2021.06-4.module_el9.1.0+13+d9a595ea

    A vulnerability was found in the minimatch package. This flaw allows a Regular Expression Denial of Service (ReDoS) when calling the braceExpand function with specific arguments, resulting in a Denial of Service.

Page 6 of 6