VYPR

rpm package

suse/nodejs-common&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP2

pkg:rpm/suse/nodejs-common&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP2

Vulnerabilities (5)

  • CVE-2021-3918Nov 13, 2021
    affected < 2.0-3.4.1fixed 2.0-3.4.1

    json-schema is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

  • CVE-2021-3807Sep 17, 2021
    affected < 2.0-3.4.1fixed 2.0-3.4.1

    ansi-regex is vulnerable to Inefficient Regular Expression Complexity

  • CVE-2021-32804Aug 3, 2021
    affected < 2.0-3.4.1fixed 2.0-3.4.1

    The npm package "tar" (aka node-tar) before versions 6.1.1, 5.0.6, 4.4.14, and 3.3.2 has a arbitrary File Creation/Overwrite vulnerability due to insufficient absolute path sanitization. node-tar aims to prevent extraction of absolute file paths by turning absolute paths into rel

  • CVE-2021-32803Aug 3, 2021
    affected < 2.0-3.4.1fixed 2.0-3.4.1

    The npm package "tar" (aka node-tar) before versions 6.1.2, 5.0.7, 4.4.15, and 3.2.3 has an arbitrary File Creation/Overwrite vulnerability via insufficient symlink protection. `node-tar` aims to guarantee that any file whose location would be modified by a symbolic link is not e

  • CVE-2021-23343May 4, 2021
    affected < 2.0-3.4.1fixed 2.0-3.4.1

    All versions of package path-parse are vulnerable to Regular Expression Denial of Service (ReDoS) via splitDeviceRe, splitTailRe, and splitPathRe regular expressions. ReDoS exhibits polynomial worst-case time complexity.