[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250363

 
 

909

 
 

196124

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

RHSA-2023:7205 -- Oracle nodejs_npm

ID: oval:org.secpod.oval:def:95287Date: (C)2023-12-01   (M)2024-04-29
Class: PATCHFamily: unix




Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Security Fix(es): * HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) (CVE-2023-44487) * nodejs: permission model improperly protects against path traversal (CVE-2023-39331) * nodejs: path traversal through path stored in Uint8Array (CVE-2023-39332) * nodejs: integrity checks according to policies can be circumvented (CVE-2023-38552) * nodejs: code injection via WebAssembly export names (CVE-2023-39333) * node-undici: cookie leakage (CVE-2023-45143)

Platform:
Red Hat Enterprise Linux 8
Product:
nodejs
npm
Reference:
RHSA-2023:7205
CVE-2023-38552
CVE-2023-39331
CVE-2023-39332
CVE-2023-39333
CVE-2023-44487
CVE-2023-45143
CVE-2022-25883
CVE    7
CVE-2023-39333
CVE-2022-25883
CVE-2023-39332
CVE-2023-39331
...
CPE    3
cpe:/a:npm:npm
cpe:/o:redhat:enterprise_linux:8
cpe:/a:nodejs:nodejs

© SecPod Technologies