Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.151749
Category:Web application abuses
Title:Node.js 20.x < 20.11.1, 21.x < 21.6.2 Multiple Vulnerabilities - Windows
Summary:Node.js is prone to multiple vulnerabilities.
Description:Summary:
Node.js is prone to multiple vulnerabilities.

Vulnerability Insight:
The following flaws exist:

- CVE-2023-5678, CVE-2023-6129, CVE-2023-6237, CVE-2024-0727: Multiple vulnerabilities in OpenSSL

- CVE-2024-22019: Reading unprocessed HTTP request with unbounded chunk extension allows DoS
attacks

- CVE-2024-21896: Path traversal by monkey-patching Buffer internals

- CVE-2024-22017: setuid() does not drop all privileges due to io_uring

- CVE-2023-46809: Node.js is vulnerable to the Marvin Attack (timing variant of the
Bleichenbacher attack against PKCS#1 v1.5 padding)

- CVE-2024-21891: Multiple permission model bypasses due to improper path traversal sequence
sanitization

- CVE-2024-21890: Improper handling of wildcards in --allow-fs-read and --allow-fs-write

- CVE-2024-22025: Denial of Service by resource exhaustion in fetch() brotli decoding

- CVE-2024-24758: Vulnerability in undici

- CVE-2024-24806: Vulnerability in libuv

Affected Software/OS:
Node.js version 20.x and 21.x.

Solution:
Update to version 20.11.1, 21.6.2 or later.

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2024-22019
https://hackerone.com/reports/2233486
http://www.openwall.com/lists/oss-security/2024/03/11/1
Common Vulnerability Exposure (CVE) ID: CVE-2024-21896
https://hackerone.com/reports/2218653
Common Vulnerability Exposure (CVE) ID: CVE-2024-22017
https://hackerone.com/reports/2170226
Common Vulnerability Exposure (CVE) ID: CVE-2023-46809
Common Vulnerability Exposure (CVE) ID: CVE-2024-21891
https://hackerone.com/reports/2259914
Common Vulnerability Exposure (CVE) ID: CVE-2024-21890
https://hackerone.com/reports/2257156
Common Vulnerability Exposure (CVE) ID: CVE-2024-22025
https://hackerone.com/reports/2284065
https://lists.debian.org/debian-lts-announce/2024/03/msg00029.html
Common Vulnerability Exposure (CVE) ID: CVE-2024-24806
https://github.com/libuv/libuv/commit/0f2d7e784a256b54b2385043438848047bc2a629
https://github.com/libuv/libuv/commit/3530bcc30350d4a6ccf35d2f7b33e23292b9de70
https://github.com/libuv/libuv/commit/c858a147643de38a09dd4164758ae5b685f2b488
https://github.com/libuv/libuv/commit/e0327e1d508b8207c9150b6e582f0adf26213c39
https://github.com/libuv/libuv/security/advisories/GHSA-f74f-cvh7-c6q6
https://lists.debian.org/debian-lts-announce/2024/03/msg00005.html
http://www.openwall.com/lists/oss-security/2024/02/08/2
http://www.openwall.com/lists/oss-security/2024/02/11/1
Common Vulnerability Exposure (CVE) ID: CVE-2024-24758
https://github.com/nodejs/undici/commit/b9da3e40f1f096a06b4caedbb27c2568730434ef
https://github.com/nodejs/undici/security/advisories/GHSA-3787-6prv-h9w3
Common Vulnerability Exposure (CVE) ID: CVE-2023-5678
1.0.2zj git commit
https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=34efaef6c103d636ab507a0cc34dca4d3aecc055
1.1.1x git commit
https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=710fee740904b6290fef0dd5536fbcedbc38ff0c
3.0.13 git commit
https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=db925ae2e65d0d925adef429afc37f75bd1c2017
3.1.5 git commit
https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=ddeb4b6c6d527e54ce9a99cba785c0f7776e54b6
OpenSSL Advisory
https://www.openssl.org/news/secadv/20231106.txt
Common Vulnerability Exposure (CVE) ID: CVE-2023-6129
https://github.com/openssl/openssl/commit/050d26383d4e264966fb83428e72d5d48f402d35
https://github.com/openssl/openssl/commit/f3fc5808fe9ff74042d639839610d03b8fdcc015
3.2.1 git commit
https://github.com/openssl/openssl/commit/5b139f95c9a47a55a0c54100f3837b1eee942b04
https://www.openssl.org/news/secadv/20240109.txt
Common Vulnerability Exposure (CVE) ID: CVE-2023-6237
https://github.com/openssl/openssl/commit/18c02492138d1eb8b6548cb26e7b625fb2414a2a
https://github.com/openssl/openssl/commit/a830f551557d3d66a84bbb18a5b889c640c36294
https://github.com/openssl/openssl/commit/0b0f7abfb37350794a4b8960fafc292cd5d1b84d
https://www.openssl.org/news/secadv/20240115.txt
Common Vulnerability Exposure (CVE) ID: CVE-2024-0727
https://github.openssl.org/openssl/extended-releases/commit/aebaa5883e31122b404e450732dc833dc9dee539
https://github.openssl.org/openssl/extended-releases/commit/03b3941d60c4bce58fab69a0c22377ab439bc0e8
https://github.com/openssl/openssl/commit/09df4395b5071217b76dc7d3d2e630eb8c5a79c2
https://github.com/openssl/openssl/commit/d135eeab8a5dbf72b3da5240bab9ddb7678dbd2c
https://github.com/openssl/openssl/commit/775acfdbd0c6af9ac855f34969cdab0c0c90844a
https://www.openssl.org/news/secadv/20240125.txt
CopyrightCopyright (C) 2024 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.