rpm package
almalinux/nodejs-packaging
pkg:rpm/almalinux/nodejs-packaging
Vulnerabilities (172)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2022-43548 | Hig | 8.1 | < 2021.06-4.module_el9.1.0+13+d9a595ea | 2021.06-4.module_el9.1.0+13+d9a595ea | Dec 5, 2022 | A OS Command Injection vulnerability exists in Node.js versions <14.21.1, <16.18.1, <18.12.1, <19.0.1 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing | |
| CVE-2022-35256 | Med | 6.5 | < 25-1.module_el8.5.0+2605+45d748af | 25-1.module_el8.5.0+2605+45d748af | Dec 5, 2022 | The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling. | |
| CVE-2022-35255 | Cri | 9.1 | < 25-1.module_el8.5.0+2605+45d748af | 25-1.module_el8.5.0+2605+45d748af | Dec 5, 2022 | A weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with EntropySource() in SecretKeyGenTraits::DoKeyGen() in src/crypto/crypto_keygen.cc. There are two problems with this: 1) It does not check the return value, it assumes EntropySource() alwa | |
| CVE-2022-38900 | Hig | 7.5 | < 23-3.module_el8.4.0+2522+3bd42762 | 23-3.module_el8.4.0+2522+3bd42762 | Nov 28, 2022 | decode-uri-component 0.2.0 is vulnerable to Improper Input Validation resulting in DoS. | |
| CVE-2022-24999 | Hig | 7.5 | < 23-3.module_el8.4.0+2522+3bd42762 | 23-3.module_el8.4.0+2522+3bd42762 | Nov 26, 2022 | qs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a Node process hang for an Express application because an __ proto__ key can be used. In many typical Express use cases, an unauthenticated remote attacker can place the attack payloa | |
| CVE-2022-3517 | Hig | 7.5 | < 2021.06-4.module_el9.1.0+13+d9a595ea | 2021.06-4.module_el9.1.0+13+d9a595ea | Oct 17, 2022 | A vulnerability was found in the minimatch package. This flaw allows a Regular Expression Denial of Service (ReDoS) when calling the braceExpand function with specific arguments, resulting in a Denial of Service. | |
| CVE-2022-32215 | Med | 6.5 | < 23-3.module_el8.5.0+2618+8d46dafd | 23-3.module_el8.5.0+2618+8d46dafd | Jul 14, 2022 | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding headers. This can lead to HTTP Request Smuggling (HRS). | |
| CVE-2022-32214 | Med | 6.5 | < 23-3.module_el8.5.0+2618+8d46dafd | 23-3.module_el8.5.0+2618+8d46dafd | Jul 14, 2022 | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS). | |
| CVE-2022-32213 | Med | 6.5 | < 23-3.module_el8.5.0+2618+8d46dafd | 23-3.module_el8.5.0+2618+8d46dafd | Jul 14, 2022 | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS). | |
| CVE-2022-32212 | Hig | 8.1 | < 23-3.module_el8.5.0+2618+8d46dafd | 23-3.module_el8.5.0+2618+8d46dafd | Jul 14, 2022 | A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding | |
| CVE-2022-33987 | Med | 5.3 | < 23-3.module_el8.5.0+2618+8d46dafd | 23-3.module_el8.5.0+2618+8d46dafd | Jun 18, 2022 | The got package before 12.1.0 (also fixed in 11.8.5) for Node.js allows a redirect to a UNIX socket. | |
| CVE-2021-44906 | Cri | 9.8 | < 25-1.module_el8.5.0+2605+45d748af | 25-1.module_el8.5.0+2605+45d748af | Mar 17, 2022 | Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95). | |
| CVE-2022-21824 | Hig | 8.2 | < 23-3.module_el8.4.0+2522+3bd42762 | 23-3.module_el8.4.0+2522+3bd42762 | Feb 24, 2022 | Due to the formatting logic of the "console.table()" function it was not safe to allow user controlled input to be passed to the "properties" parameter while simultaneously passing a plain object with at least one property as the first parameter, which could be "__proto__". The p | |
| CVE-2021-44533 | Med | 5.3 | < 23-3.module_el8.4.0+2522+3bd42762 | 23-3.module_el8.4.0+2522+3bd42762 | Feb 24, 2022 | Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguished Names correctly. Attackers could craft certificate subjects containing a single-value Relative Distinguished Name that would be interpreted as a multi-value Relative Distinguis | |
| CVE-2021-44532 | Med | 5.3 | < 23-3.module_el8.4.0+2522+3bd42762 | 23-3.module_el8.4.0+2522+3bd42762 | Feb 24, 2022 | Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 converts SANs (Subject Alternative Names) to a string format. It uses this string to check peer certificates against hostnames when validating connections. The string format was subject to an injection vulnerability when name | |
| CVE-2021-44531 | Hig | 7.4 | < 23-3.module_el8.4.0+2522+3bd42762 | 23-3.module_el8.4.0+2522+3bd42762 | Feb 24, 2022 | Accepting arbitrary Subject Alternative Name (SAN) types, unless a PKI is specifically defined to use a particular SAN type, can result in bypassing name-constrained intermediates. Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 was accepting URI SAN types, which PKIs are o | |
| CVE-2022-0235 | Med | 6.1 | < 23-3.module_el8.4.0+2522+3bd42762 | 23-3.module_el8.4.0+2522+3bd42762 | Jan 16, 2022 | node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor | |
| CVE-2021-3672 | Med | 5.6 | < 17-3.module_el8.4.0+2224+b07ac28e | 17-3.module_el8.4.0+2224+b07ac28e | Nov 23, 2021 | A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality | |
| CVE-2021-22959 | Med | 6.5 | < 25-1.module_el8.5.0+246+05401605 | 25-1.module_el8.5.0+246+05401605 | Nov 15, 2021 | The parser in accepts requests with a space (SP) right after the header name before the colon. This can lead to HTTP Request Smuggling (HRS) in llhttp < v2.1.4 and < v6.0.6. | |
| CVE-2021-43616 | Cri | 9.0 | < 25-1.module_el8.5.0+246+05401605 | 25-1.module_el8.5.0+246+05401605 | Nov 13, 2021 | The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differs from package.json. This behavior is inconsistent with the documentation, and makes it easier for attackers to install malware that was sup |
- affected < 2021.06-4.module_el9.1.0+13+d9a595eafixed 2021.06-4.module_el9.1.0+13+d9a595ea
A OS Command Injection vulnerability exists in Node.js versions <14.21.1, <16.18.1, <18.12.1, <19.0.1 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing
- affected < 25-1.module_el8.5.0+2605+45d748affixed 25-1.module_el8.5.0+2605+45d748af
The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling.
- affected < 25-1.module_el8.5.0+2605+45d748affixed 25-1.module_el8.5.0+2605+45d748af
A weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with EntropySource() in SecretKeyGenTraits::DoKeyGen() in src/crypto/crypto_keygen.cc. There are two problems with this: 1) It does not check the return value, it assumes EntropySource() alwa
- affected < 23-3.module_el8.4.0+2522+3bd42762fixed 23-3.module_el8.4.0+2522+3bd42762
decode-uri-component 0.2.0 is vulnerable to Improper Input Validation resulting in DoS.
- affected < 23-3.module_el8.4.0+2522+3bd42762fixed 23-3.module_el8.4.0+2522+3bd42762
qs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a Node process hang for an Express application because an __ proto__ key can be used. In many typical Express use cases, an unauthenticated remote attacker can place the attack payloa
- affected < 2021.06-4.module_el9.1.0+13+d9a595eafixed 2021.06-4.module_el9.1.0+13+d9a595ea
A vulnerability was found in the minimatch package. This flaw allows a Regular Expression Denial of Service (ReDoS) when calling the braceExpand function with specific arguments, resulting in a Denial of Service.
- affected < 23-3.module_el8.5.0+2618+8d46dafdfixed 23-3.module_el8.5.0+2618+8d46dafd
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding headers. This can lead to HTTP Request Smuggling (HRS).
- affected < 23-3.module_el8.5.0+2618+8d46dafdfixed 23-3.module_el8.5.0+2618+8d46dafd
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS).
- affected < 23-3.module_el8.5.0+2618+8d46dafdfixed 23-3.module_el8.5.0+2618+8d46dafd
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS).
- affected < 23-3.module_el8.5.0+2618+8d46dafdfixed 23-3.module_el8.5.0+2618+8d46dafd
A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding
- affected < 23-3.module_el8.5.0+2618+8d46dafdfixed 23-3.module_el8.5.0+2618+8d46dafd
The got package before 12.1.0 (also fixed in 11.8.5) for Node.js allows a redirect to a UNIX socket.
- affected < 25-1.module_el8.5.0+2605+45d748affixed 25-1.module_el8.5.0+2605+45d748af
Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95).
- affected < 23-3.module_el8.4.0+2522+3bd42762fixed 23-3.module_el8.4.0+2522+3bd42762
Due to the formatting logic of the "console.table()" function it was not safe to allow user controlled input to be passed to the "properties" parameter while simultaneously passing a plain object with at least one property as the first parameter, which could be "__proto__". The p
- affected < 23-3.module_el8.4.0+2522+3bd42762fixed 23-3.module_el8.4.0+2522+3bd42762
Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguished Names correctly. Attackers could craft certificate subjects containing a single-value Relative Distinguished Name that would be interpreted as a multi-value Relative Distinguis
- affected < 23-3.module_el8.4.0+2522+3bd42762fixed 23-3.module_el8.4.0+2522+3bd42762
Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 converts SANs (Subject Alternative Names) to a string format. It uses this string to check peer certificates against hostnames when validating connections. The string format was subject to an injection vulnerability when name
- affected < 23-3.module_el8.4.0+2522+3bd42762fixed 23-3.module_el8.4.0+2522+3bd42762
Accepting arbitrary Subject Alternative Name (SAN) types, unless a PKI is specifically defined to use a particular SAN type, can result in bypassing name-constrained intermediates. Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 was accepting URI SAN types, which PKIs are o
- affected < 23-3.module_el8.4.0+2522+3bd42762fixed 23-3.module_el8.4.0+2522+3bd42762
node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
- affected < 17-3.module_el8.4.0+2224+b07ac28efixed 17-3.module_el8.4.0+2224+b07ac28e
A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality
- affected < 25-1.module_el8.5.0+246+05401605fixed 25-1.module_el8.5.0+246+05401605
The parser in accepts requests with a space (SP) right after the header name before the colon. This can lead to HTTP Request Smuggling (HRS) in llhttp < v2.1.4 and < v6.0.6.
- affected < 25-1.module_el8.5.0+246+05401605fixed 25-1.module_el8.5.0+246+05401605
The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differs from package.json. This behavior is inconsistent with the documentation, and makes it easier for attackers to install malware that was sup
Page 6 of 9