rpm package
suse/nodejs12&distro=SUSE Enterprise Storage 7
pkg:rpm/suse/nodejs12&distro=SUSE%20Enterprise%20Storage%207
Vulnerabilities (22)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2021-32803 | — | < 12.22.10-4.29.3 | 12.22.10-4.29.3 | Aug 3, 2021 | The npm package "tar" (aka node-tar) before versions 6.1.2, 5.0.7, 4.4.15, and 3.2.3 has an arbitrary File Creation/Overwrite vulnerability via insufficient symlink protection. `node-tar` aims to guarantee that any file whose location would be modified by a symbolic link is not e | ||
| CVE-2021-23343 | — | < 12.22.10-4.29.3 | 12.22.10-4.29.3 | May 4, 2021 | All versions of package path-parse are vulnerable to Regular Expression Denial of Service (ReDoS) via splitDeviceRe, splitTailRe, and splitPathRe regular expressions. ReDoS exhibits polynomial worst-case time complexity. |
- CVE-2021-32803Aug 3, 2021affected < 12.22.10-4.29.3fixed 12.22.10-4.29.3
The npm package "tar" (aka node-tar) before versions 6.1.2, 5.0.7, 4.4.15, and 3.2.3 has an arbitrary File Creation/Overwrite vulnerability via insufficient symlink protection. `node-tar` aims to guarantee that any file whose location would be modified by a symbolic link is not e
- CVE-2021-23343May 4, 2021affected < 12.22.10-4.29.3fixed 12.22.10-4.29.3
All versions of package path-parse are vulnerable to Regular Expression Denial of Service (ReDoS) via splitDeviceRe, splitTailRe, and splitPathRe regular expressions. ReDoS exhibits polynomial worst-case time complexity.
Page 2 of 2