Known vulnerabilities in nodejs (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:nodejs_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 44
Public exploits: 2
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting nodejs (Red Hat package) nodejs (Red Hat package) is affected by 44 known vulnerabilities: 4 high, 35 medium, 5 low Critical High Medium Low

Vulnerabilities (44)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU88176 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2024-27982
CWE-444 Medium
No
No
16.20.2-6.el9_0, 16.20.2-6.el9_2.3, 16.20.2-8.el9_4 05.04.2024 SB2024040526
SB2024040851
SB2024040852
and 53 more
#VU88175 - Reachable Assertion
CVE-2024-27983
CWE-617 Medium
Available
No
16.20.2-5.el9_2.3, 16.20.2-6.el9_0, 16.20.2-8.el9_4 05.04.2024 SB2024040526
SB2024040851
SB2024040852
and 56 more
#VU88144 - Improper input validation
CVE-2024-28182
CWE-20 Medium
No
No
16.20.2-5.el9_2.3, 16.20.2-8.el9_4, 16.20.2-9.el9_0 04.04.2024 SB2024040442
SB2024040443
SB2024040444
and 124 more
#VU86807 - Out-of-bounds read
CVE-2024-25629
CWE-125 Low
No
No
16.20.2-6.el9_2.3, 16.20.2-8.el9_4, 16.20.2-9.el9_0 26.02.2024 SB2024022648
SB2024030621
SB2024032954
and 38 more
#VU86733 - Improper input validation
CVE-2024-22025
CWE-20 Medium
No
No
16.20.2-6.el9_2.3, 16.20.2-8.el9_4, 16.20.2-9.el9_0 22.02.2024 SB2024022225
SB2024022226
SB2024022832
and 34 more
#VU86721 - Improper input validation
CVE-2024-22019
CWE-20 Medium
No
No
16.20.2-4.el9_0, 16.20.2-4.el9_2, 16.20.2-4.el9_3 22.02.2024 SB2024022225
SB2024022226
SB2024022832
and 48 more
#VU81728 - Resource exhaustion
CVE-2023-44487
CWE-400 High
Available
Exploited
16.20.2-3.el9_0, 16.20.2-3.el9_2 10.10.2023 SB2023101023
SB2023101024
SB2023101037
and 650 more
#VU79335 - Permissions, Privileges, and Access Controls
CVE-2023-32559
CWE-264 Medium
No
No
16.20.2-1.el9_0, 16.20.2-1.el9_2 10.08.2023 SB2023081012
SB2023081443
SB2023081705
and 39 more
#VU79334 - Permissions, Privileges, and Access Controls
CVE-2023-32006
CWE-264 Medium
No
No
16.20.2-1.el9_0, 16.20.2-1.el9_2 10.08.2023 SB2023081012
SB2023081443
SB2023081705
and 38 more
#VU79332 - Permissions, Privileges, and Access Controls
CVE-2023-32002
CWE-264 Medium
No
No
16.20.2-1.el9_0, 16.20.2-1.el9_2 10.08.2023 SB2023081012
SB2023081443
SB2023081705
and 44 more
#VU77606 - Inconsistency Between Implementation and Documented Design
CVE-2023-30590
CWE-1068 Medium
No
No
16.20.1-1.el9_2, 16.20.2-1.el9_0 21.06.2023 SB2023062144
SB2023062727
SB2023062743
and 33 more
#VU77605 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2023-30589
CWE-444 Medium
No
No
16.20.1-1.el9_2, 16.20.2-1.el9_0 21.06.2023 SB2023062144
SB2023062727
SB2023062743
and 43 more
#VU77604 - Improper input validation
CVE-2023-30588
CWE-20 Medium
No
No
16.20.1-1.el9_2, 16.20.2-1.el9_0 21.06.2023 SB2023062144
SB2023062727
SB2023062743
and 33 more
#VU77586 - Permissions, Privileges, and Access Controls
CVE-2023-30581
CWE-264 Medium
No
No
16.20.1-1.el9_2, 16.20.2-1.el9_0 21.06.2023 SB2023062144
SB2023062727
SB2023062743
and 31 more
#VU76426 - Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
CVE-2023-31147
CWE-338 Medium
No
No
16.18.1-4.el9_0, 16.19.1-2.el9_2 23.05.2023 SB2023052309
SB2023052312
SB2023053021
and 39 more
#VU76425 - Buffer Underwrite ('Buffer Underflow')
CVE-2023-31130
CWE-124 Low
No
No
16.18.1-4.el9_0, 16.19.1-2.el9_2 23.05.2023 SB2023052309
SB2023052312
SB2023053021
and 55 more
#VU76424 - Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
CVE-2023-31124
CWE-338 Medium
No
No
16.18.1-4.el9_0, 16.19.1-2.el9_2 23.05.2023 SB2023052309
SB2023052312
SB2023053021
and 33 more
#VU76423 - Improper input validation
CVE-2023-32067
CWE-20 Medium
No
No
16.18.1-4.el9_0, 16.19.1-2.el9_2 23.05.2023 SB2023052312
SB2023053021
SB2023060711
and 35 more
#VU76422 - Improper input validation
CVE-2023-32067
CWE-20 Medium
No
No
16.18.1-4.el9_0, 16.19.1-2.el9_2 23.05.2023 SB2023052309
SB2023052312
SB2023053021
and 66 more
#VU72750 - Inefficient Algorithmic Complexity
CVE-2022-25881
CWE-407 Medium
No
No
16.19.1-1.el9_2, 16.20.2-1.el9_0 03.03.2023 SB2023030326
SB2023030328
SB2023031112
and 61 more


Showing elements 1 - 20 out of 44