VYPR

rpm package

opensuse/nodejs18&distro=openSUSE Leap 15.4

pkg:rpm/opensuse/nodejs18&distro=openSUSE%20Leap%2015.4

Vulnerabilities (25)

  • CVE-2022-35255Dec 5, 2022
    affected < 18.13.0-150400.9.3.1fixed 18.13.0-150400.9.3.1

    A weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with EntropySource() in SecretKeyGenTraits::DoKeyGen() in src/crypto/crypto_keygen.cc. There are two problems with this: 1) It does not check the return value, it assumes EntropySource() alwa

  • CVE-2022-32215Jul 14, 2022
    affected < 18.13.0-150400.9.3.1fixed 18.13.0-150400.9.3.1

    The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding headers. This can lead to HTTP Request Smuggling (HRS).

  • CVE-2022-32214Jul 14, 2022
    affected < 18.13.0-150400.9.3.1fixed 18.13.0-150400.9.3.1

    The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS).

  • CVE-2022-32213Jul 14, 2022
    affected < 18.13.0-150400.9.3.1fixed 18.13.0-150400.9.3.1

    The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS).

  • CVE-2022-32212Jul 14, 2022
    affected < 18.13.0-150400.9.3.1fixed 18.13.0-150400.9.3.1

    A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding

Page 2 of 2