rpm package
opensuse/nodejs20&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/nodejs20&distro=openSUSE%20Tumbleweed
Vulnerabilities (41)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2023-30586 | Hig | 7.5 | < 20.3.1-1.1 | 20.3.1-1.1 | Jul 1, 2023 | A privilege escalation vulnerability exists in Node.js 20 that allowed loading arbitrary OpenSSL engines when the experimental permission model is enabled, which can bypass and/or disable the permission model. The attack complexity is high. However, the crypto.setEngine() API can |
- affected < 20.3.1-1.1fixed 20.3.1-1.1
A privilege escalation vulnerability exists in Node.js 20 that allowed loading arbitrary OpenSSL engines when the experimental permission model is enabled, which can bypass and/or disable the permission model. The attack complexity is high. However, the crypto.setEngine() API can
Page 3 of 3