Nodered
Products
2- 3 CVEs
- 3 CVEs
Recent CVEs
6| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-21297 | Hig | 0.50 | 7.7 | 0.01 | Feb 26, 2021 | Node-Red is a low-code programming for event-driven applications built using nodejs. Node-RED 1.2.7 and earlier contains a Prototype Pollution vulnerability in the admin API. A badly formed request can modify the prototype of the default JavaScript Object with the potential to… | ||
| CVE-2021-3223 | Hig | 0.43 | 7.5 | 0.19 | Jan 26, 2021 | Node-RED-Dashboard before 2.26.2 allows ui_base/js/..%2f directory traversal to read files. | ||
| CVE-2019-15607 | Med | 0.35 | 5.4 | 0.01 | Jan 28, 2020 | A stored XSS vulnerability is present within node-red (version: <= 0.20.7) npm package, which is a visual tool for wiring the Internet of Things. This issue will allow the attacker to steal session cookies, deface web applications, etc. | ||
| CVE-2019-10756 | Med | 0.35 | 5.4 | 0.01 | Oct 8, 2019 | It is possible to inject JavaScript within node-red-dashboard versions prior to version 2.17.0 due to the ui_notification node accepting raw HTML by default. | ||
| CVE-2022-3783 | Low | 0.16 | 3.5 | 0.01 | Oct 31, 2022 | A vulnerability, which was classified as problematic, has been found in node-red-dashboard. This issue affects some unknown processing of the file components/ui-component/ui-component-ctrl.js of the component ui_text Format Handler. The manipulation leads to cross site… | ||
| CVE-2021-21298 | Low | 0.16 | 3.5 | 0.01 | Feb 26, 2021 | Node-Red is a low-code programming for event-driven applications built using nodejs. Node-RED 1.2.7 and earlier has a vulnerability which allows arbitrary path traversal via the Projects API. If the Projects feature is enabled, a user with `projects.read` permission is able to… |
- risk 0.50cvss 7.7epss 0.01
Node-Red is a low-code programming for event-driven applications built using nodejs. Node-RED 1.2.7 and earlier contains a Prototype Pollution vulnerability in the admin API. A badly formed request can modify the prototype of the default JavaScript Object with the potential to…
- risk 0.43cvss 7.5epss 0.19
Node-RED-Dashboard before 2.26.2 allows ui_base/js/..%2f directory traversal to read files.
- risk 0.35cvss 5.4epss 0.01
A stored XSS vulnerability is present within node-red (version: <= 0.20.7) npm package, which is a visual tool for wiring the Internet of Things. This issue will allow the attacker to steal session cookies, deface web applications, etc.
- risk 0.35cvss 5.4epss 0.01
It is possible to inject JavaScript within node-red-dashboard versions prior to version 2.17.0 due to the ui_notification node accepting raw HTML by default.
- risk 0.16cvss 3.5epss 0.01
A vulnerability, which was classified as problematic, has been found in node-red-dashboard. This issue affects some unknown processing of the file components/ui-component/ui-component-ctrl.js of the component ui_text Format Handler. The manipulation leads to cross site…
- risk 0.16cvss 3.5epss 0.01
Node-Red is a low-code programming for event-driven applications built using nodejs. Node-RED 1.2.7 and earlier has a vulnerability which allows arbitrary path traversal via the Projects API. If the Projects feature is enabled, a user with `projects.read` permission is able to…