rpm package
almalinux/nodejs-packaging
pkg:rpm/almalinux/nodejs-packaging
Vulnerabilities (172)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2020-8265 | Hig | 8.1 | < 17-3.module_el8.4.0+2224+b07ac28e | 17-3.module_el8.4.0+2224+b07ac28e | Jan 6, 2021 | Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 are vulnerable to a use-after-free bug in its TLS implementation. When writing to a TLS enabled socket, node::StreamBase::Write calls node::TLSWrap::DoWrite with a freshly allocated WriteWrap object as first argument. If t | |
| CVE-2020-7788 | Hig | 7.3 | < 17-3.module_el8.4.0+2224+b07ac28e | 17-3.module_el8.4.0+2224+b07ac28e | Dec 11, 2020 | This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be exploited further depending on the context. | |
| CVE-2020-8277 | Hig | 7.5 | < 17-3.module_el8.4.0+2224+b07ac28e | 17-3.module_el8.4.0+2224+b07ac28e | Nov 19, 2020 | A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versions < 15.2.1, < 14.15.1, and < 12.19.1 by getting the application to resolve a DNS record with a larger number of responses. This is fixed i | |
| CVE-2020-7774 | Hig | 7.3 | < 17-3.module_el8.4.0+2224+b07ac28e | 17-3.module_el8.4.0+2224+b07ac28e | Nov 17, 2020 | The package y18n before 3.2.2, 4.0.1 and 5.0.5, is vulnerable to Prototype Pollution. | |
| CVE-2020-7754 | Hig | 7.5 | < 17-3.module_el8.4.0+2224+b07ac28e | 17-3.module_el8.4.0+2224+b07ac28e | Oct 27, 2020 | This affects the package npm-user-validate before 1.0.1. The regex that validates user emails took exponentially longer to process long input strings beginning with @ characters. | |
| CVE-2020-8252 | Hig | 7.8 | < 17-3.module_el8.4.0+2224+b07ac28e | 17-3.module_el8.4.0+2224+b07ac28e | Sep 18, 2020 | The implementation of realpath in libuv < 10.22.1, < 12.18.4, and < 14.9.0 used within Node.js incorrectly determined the buffer size which can result in a buffer overflow if the resolved path is longer than 256 bytes. | |
| CVE-2020-8201 | Hig | 7.4 | < 17-3.module_el8.4.0+2224+b07ac28e | 17-3.module_el8.4.0+2224+b07ac28e | Sep 18, 2020 | Node.js < 12.18.4 and < 14.11 can be exploited to perform HTTP desync attacks and deliver malicious payloads to unsuspecting users. The payloads can be crafted by an attacker to hijack user sessions, poison cookies, perform clickjacking, and a multitude of other attacks depending | |
| CVE-2020-8174 | Hig | 8.1 | < 17-3.module_el8.4.0+2224+b07ac28e | 17-3.module_el8.4.0+2224+b07ac28e | Jul 24, 2020 | napi_get_value_string_*() allows various kinds of memory corruption in node < 10.21.0, 12.18.0, and < 14.4.0. | |
| CVE-2020-15366 | Med | 5.6 | < 17-3.module_el8.4.0+2224+b07ac28e | 17-3.module_el8.4.0+2224+b07ac28e | Jul 15, 2020 | An issue was discovered in ajv.validate() in Ajv (aka Another JSON Schema Validator) 6.12.2. A carefully crafted JSON schema could be provided that allows execution of other code by prototype pollution. (While untrusted schemas are recommended against, the worst case of an untrus | |
| CVE-2020-15095 | Med | 4.4 | < 17-3.module_el8.4.0+2224+b07ac28e | 17-3.module_el8.4.0+2224+b07ac28e | Jul 7, 2020 | Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The CLI supports URLs like "://[[:]@][:][:][/]". The password value is not redacted and is printed to stdout and also | |
| CVE-2020-8172 | Hig | 7.4 | < 17-3.module_el8.4.0+2224+b07ac28e | 17-3.module_el8.4.0+2224+b07ac28e | Jun 8, 2020 | TLS session reuse can lead to host certificate verification bypass in node version < 12.18.0 and < 14.4.0. | |
| CVE-2020-11080 | Low | 3.7 | < 17-3.module_el8.4.0+2224+b07ac28e | 17-3.module_el8.4.0+2224+b07ac28e | Jun 3, 2020 | In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a malicious client constructing a SETTINGS frame with a length of 14,400 bytes (2400 individual settings entries) over and over again. T | |
| CVE-2020-7608 | Med | 5.3 | < 17-3.module_el8.4.0+2224+b07ac28e | 17-3.module_el8.4.0+2224+b07ac28e | Mar 16, 2020 | yargs-parser could be tricked into adding or modifying properties of Object.prototype using a "__proto__" payload. | |
| CVE-2020-10531 | Hig | 8.8 | < 17-3.module_el8.4.0+2224+b07ac28e | 17-3.module_el8.4.0+2224+b07ac28e | Mar 12, 2020 | An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An integer overflow, leading to a heap-based buffer overflow, exists in the UnicodeString::doAppend() function in common/unistr.cpp. | |
| CVE-2020-7598 | Med | 5.6 | < 17-3.module_el8.4.0+2224+b07ac28e | 17-3.module_el8.4.0+2224+b07ac28e | Mar 11, 2020 | minimist before 1.2.2 could be tricked into adding or modifying properties of Object.prototype using a "constructor" or "__proto__" payload. | |
| CVE-2019-15606 | Cri | 9.8 | < 17-3.module_el8.4.0+2224+b07ac28e | 17-3.module_el8.4.0+2224+b07ac28e | Feb 7, 2020 | Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons | |
| CVE-2019-15605 | Cri | 9.8 | < 17-3.module_el8.4.0+2224+b07ac28e | 17-3.module_el8.4.0+2224+b07ac28e | Feb 7, 2020 | HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed | |
| CVE-2019-15604 | Hig | 7.5 | < 17-3.module_el8.4.0+2224+b07ac28e | 17-3.module_el8.4.0+2224+b07ac28e | Feb 7, 2020 | Improper Certificate Validation in Node.js 10, 12, and 13 causes the process to abort when sending a crafted X.509 certificate | |
| CVE-2020-8116 | Hig | 7.3 | < 17-3.module_el8.4.0+2224+b07ac28e | 17-3.module_el8.4.0+2224+b07ac28e | Feb 4, 2020 | Prototype pollution vulnerability in dot-prop npm package versions before 4.2.1 and versions 5.x before 5.1.1 allows an attacker to add arbitrary properties to JavaScript language constructs such as objects. | |
| CVE-2019-16777 | Hig | 7.7 | < 17-3.module_el8.4.0+2224+b07ac28e | 17-3.module_el8.4.0+2224+b07ac28e | Dec 13, 2019 | Versions of the npm CLI prior to 6.13.4 are vulnerable to an Arbitrary File Overwrite. It fails to prevent existing globally-installed binaries to be overwritten by other package installations. For example, if a package was installed globally and created a serve binary, any subse |
- affected < 17-3.module_el8.4.0+2224+b07ac28efixed 17-3.module_el8.4.0+2224+b07ac28e
Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 are vulnerable to a use-after-free bug in its TLS implementation. When writing to a TLS enabled socket, node::StreamBase::Write calls node::TLSWrap::DoWrite with a freshly allocated WriteWrap object as first argument. If t
- affected < 17-3.module_el8.4.0+2224+b07ac28efixed 17-3.module_el8.4.0+2224+b07ac28e
This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be exploited further depending on the context.
- affected < 17-3.module_el8.4.0+2224+b07ac28efixed 17-3.module_el8.4.0+2224+b07ac28e
A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versions < 15.2.1, < 14.15.1, and < 12.19.1 by getting the application to resolve a DNS record with a larger number of responses. This is fixed i
- affected < 17-3.module_el8.4.0+2224+b07ac28efixed 17-3.module_el8.4.0+2224+b07ac28e
The package y18n before 3.2.2, 4.0.1 and 5.0.5, is vulnerable to Prototype Pollution.
- affected < 17-3.module_el8.4.0+2224+b07ac28efixed 17-3.module_el8.4.0+2224+b07ac28e
This affects the package npm-user-validate before 1.0.1. The regex that validates user emails took exponentially longer to process long input strings beginning with @ characters.
- affected < 17-3.module_el8.4.0+2224+b07ac28efixed 17-3.module_el8.4.0+2224+b07ac28e
The implementation of realpath in libuv < 10.22.1, < 12.18.4, and < 14.9.0 used within Node.js incorrectly determined the buffer size which can result in a buffer overflow if the resolved path is longer than 256 bytes.
- affected < 17-3.module_el8.4.0+2224+b07ac28efixed 17-3.module_el8.4.0+2224+b07ac28e
Node.js < 12.18.4 and < 14.11 can be exploited to perform HTTP desync attacks and deliver malicious payloads to unsuspecting users. The payloads can be crafted by an attacker to hijack user sessions, poison cookies, perform clickjacking, and a multitude of other attacks depending
- affected < 17-3.module_el8.4.0+2224+b07ac28efixed 17-3.module_el8.4.0+2224+b07ac28e
napi_get_value_string_*() allows various kinds of memory corruption in node < 10.21.0, 12.18.0, and < 14.4.0.
- affected < 17-3.module_el8.4.0+2224+b07ac28efixed 17-3.module_el8.4.0+2224+b07ac28e
An issue was discovered in ajv.validate() in Ajv (aka Another JSON Schema Validator) 6.12.2. A carefully crafted JSON schema could be provided that allows execution of other code by prototype pollution. (While untrusted schemas are recommended against, the worst case of an untrus
- affected < 17-3.module_el8.4.0+2224+b07ac28efixed 17-3.module_el8.4.0+2224+b07ac28e
Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The CLI supports URLs like "://[[:]@][:][:][/]". The password value is not redacted and is printed to stdout and also
- affected < 17-3.module_el8.4.0+2224+b07ac28efixed 17-3.module_el8.4.0+2224+b07ac28e
TLS session reuse can lead to host certificate verification bypass in node version < 12.18.0 and < 14.4.0.
- affected < 17-3.module_el8.4.0+2224+b07ac28efixed 17-3.module_el8.4.0+2224+b07ac28e
In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a malicious client constructing a SETTINGS frame with a length of 14,400 bytes (2400 individual settings entries) over and over again. T
- affected < 17-3.module_el8.4.0+2224+b07ac28efixed 17-3.module_el8.4.0+2224+b07ac28e
yargs-parser could be tricked into adding or modifying properties of Object.prototype using a "__proto__" payload.
- affected < 17-3.module_el8.4.0+2224+b07ac28efixed 17-3.module_el8.4.0+2224+b07ac28e
An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An integer overflow, leading to a heap-based buffer overflow, exists in the UnicodeString::doAppend() function in common/unistr.cpp.
- affected < 17-3.module_el8.4.0+2224+b07ac28efixed 17-3.module_el8.4.0+2224+b07ac28e
minimist before 1.2.2 could be tricked into adding or modifying properties of Object.prototype using a "constructor" or "__proto__" payload.
- affected < 17-3.module_el8.4.0+2224+b07ac28efixed 17-3.module_el8.4.0+2224+b07ac28e
Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons
- affected < 17-3.module_el8.4.0+2224+b07ac28efixed 17-3.module_el8.4.0+2224+b07ac28e
HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed
- affected < 17-3.module_el8.4.0+2224+b07ac28efixed 17-3.module_el8.4.0+2224+b07ac28e
Improper Certificate Validation in Node.js 10, 12, and 13 causes the process to abort when sending a crafted X.509 certificate
- affected < 17-3.module_el8.4.0+2224+b07ac28efixed 17-3.module_el8.4.0+2224+b07ac28e
Prototype pollution vulnerability in dot-prop npm package versions before 4.2.1 and versions 5.x before 5.1.1 allows an attacker to add arbitrary properties to JavaScript language constructs such as objects.
- affected < 17-3.module_el8.4.0+2224+b07ac28efixed 17-3.module_el8.4.0+2224+b07ac28e
Versions of the npm CLI prior to 6.13.4 are vulnerable to an Arbitrary File Overwrite. It fails to prevent existing globally-installed binaries to be overwritten by other package installations. For example, if a package was installed globally and created a serve binary, any subse
Page 8 of 9