VYPR

rpm package

suse/nodejs14&distro=SUSE Enterprise Storage 7

pkg:rpm/suse/nodejs14&distro=SUSE%20Enterprise%20Storage%207

Vulnerabilities (16)

  • CVE-2023-23920Feb 23, 2023
    affected < 14.21.3-150200.15.43.1fixed 14.21.3-150200.15.43.1

    An untrusted search path vulnerability exists in Node.js. <19.6.1, <18.14.1, <16.19.1, and <14.21.3 that could allow an attacker to search and potentially load ICU data when running with elevated privileges.

  • CVE-2023-23918Feb 23, 2023
    affected < 14.21.3-150200.15.43.1fixed 14.21.3-150200.15.43.1

    A privilege escalation vulnerability exists in Node.js <19.6.1, <18.14.1, <16.19.1 and <14.21.3 that made it possible to bypass the experimental Permissions (https://nodejs.org/api/permissions.html) feature in Node.js and access non authorized modules by using process.mainModule.

  • CVE-2022-25881Jan 31, 2023
    affected < 14.21.3-150200.15.46.1fixed 14.21.3-150200.15.46.1

    This affects versions of the package http-cache-semantics before 4.1.1. The issue can be exploited via malicious request header values sent to a server, when that server reads the cache policy from the request using this library.

  • CVE-2022-43548Dec 5, 2022
    affected < 14.21.1-150200.15.40.2fixed 14.21.1-150200.15.40.2

    A OS Command Injection vulnerability exists in Node.js versions <14.21.1, <16.18.1, <18.12.1, <19.0.1 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing

  • CVE-2022-32215Jul 14, 2022
    affected < 14.20.0-150200.15.34.1fixed 14.20.0-150200.15.34.1

    The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding headers. This can lead to HTTP Request Smuggling (HRS).

  • CVE-2022-32214Jul 14, 2022
    affected < 14.20.0-150200.15.34.1fixed 14.20.0-150200.15.34.1

    The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS).

  • CVE-2022-32213Jul 14, 2022
    affected < 14.20.0-150200.15.34.1fixed 14.20.0-150200.15.34.1

    The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS).

  • CVE-2022-32212Jul 14, 2022
    affected < 14.20.0-150200.15.34.1fixed 14.20.0-150200.15.34.1

    A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding

  • CVE-2021-44906Mar 17, 2022
    affected < 14.19.1-150200.15.31.1fixed 14.19.1-150200.15.31.1

    Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95).

  • CVE-2022-0778HigMar 15, 2022
    affected < 14.19.1-150200.15.31.1fixed 14.19.1-150200.15.31.1

    The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic curv

  • CVE-2022-0235Jan 16, 2022
    affected < 14.19.1-150200.15.31.1fixed 14.19.1-150200.15.31.1

    node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

  • CVE-2021-3918Nov 13, 2021
    affected < 14.19.0-15.27.1fixed 14.19.0-15.27.1

    json-schema is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

  • CVE-2021-3807Sep 17, 2021
    affected < 14.19.0-15.27.1fixed 14.19.0-15.27.1

    ansi-regex is vulnerable to Inefficient Regular Expression Complexity

  • CVE-2021-32804Aug 3, 2021
    affected < 14.19.0-15.27.1fixed 14.19.0-15.27.1

    The npm package "tar" (aka node-tar) before versions 6.1.1, 5.0.6, 4.4.14, and 3.3.2 has a arbitrary File Creation/Overwrite vulnerability due to insufficient absolute path sanitization. node-tar aims to prevent extraction of absolute file paths by turning absolute paths into rel

  • CVE-2021-32803Aug 3, 2021
    affected < 14.19.0-15.27.1fixed 14.19.0-15.27.1

    The npm package "tar" (aka node-tar) before versions 6.1.2, 5.0.7, 4.4.15, and 3.2.3 has an arbitrary File Creation/Overwrite vulnerability via insufficient symlink protection. `node-tar` aims to guarantee that any file whose location would be modified by a symbolic link is not e

  • CVE-2021-23343May 4, 2021
    affected < 14.19.0-15.27.1fixed 14.19.0-15.27.1

    All versions of package path-parse are vulnerable to Regular Expression Denial of Service (ReDoS) via splitDeviceRe, splitTailRe, and splitPathRe regular expressions. ReDoS exhibits polynomial worst-case time complexity.