Known vulnerabilities in rh-nodejs12-nodejs (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:rh-nodejs12-nodejs_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 43
Public exploits: 2
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting rh-nodejs12-nodejs (Red Hat package) rh-nodejs12-nodejs (Red Hat package) is affected by 43 known vulnerabilities: 8 high, 34 medium, 1 low Critical High Medium Low

Vulnerabilities (43)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU66955 - Improper Control of Generation of Code ('Code Injection')
CVE-2020-7788
CWE-94 Medium
No
No
12.20.1-1.el7, 12.22.5-1.el7 05.09.2022 SB2020121120
SB2022090501
SB2022091209
and 21 more
#VU64034 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-3918
CWE-94 High
No
No
12.22.12-2.el7 07.06.2022 SB2021111302
SB2022060836
SB2022071504
and 45 more
#VU64030 - Resource exhaustion
CVE-2021-44906
CWE-400 High
No
No
12.22.12-2.el7 07.06.2022 SB2022060836
SB2022062103
SB2022062203
and 52 more
#VU61254 - Use After Free
CVE-2021-22940
CWE-416 Medium
No
No
12.22.5-1.el7 11.03.2022 SB2021081615
SB2022031104
SB2022060618
and 23 more
#VU61253 - Improper Certificate Validation
CVE-2021-22939
CWE-295 Medium
No
No
12.22.5-1.el7 11.03.2022 SB2021081614
SB2022031104
SB2022060618
and 25 more
#VU59551 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-21824
CWE-94 Medium
No
No
12.22.12-2.el7 12.01.2022 SB2022011216
SB2022041205
SB2022060315
and 39 more
#VU59550 - Improper Certificate Validation
CVE-2021-44533
CWE-295 Medium
No
No
12.22.12-2.el7 12.01.2022 SB2022011216
SB2022041522
SB2022042517
and 36 more
#VU59549 - Improper Validation of Certificate with Host Mismatch
CVE-2021-44532
CWE-297 Medium
No
No
12.22.12-2.el7 12.01.2022 SB2022011216
SB2022041522
SB2022042806
and 36 more
#VU59548 - Improper Certificate Validation
CVE-2021-44531
CWE-295 Medium
No
No
12.22.12-2.el7 12.01.2022 SB2022011216
SB2022032010
SB2022041522
and 35 more
#VU59234 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2021-22960
CWE-444 Medium
No
No
12.22.12-2.el7 05.01.2022 SB2022010523
SB2022010524
SB2022042806
and 40 more
#VU59233 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2021-22959
CWE-444 Medium
No
No
12.22.12-2.el7 05.01.2022 SB2022010523
SB2022010524
SB2022011841
and 43 more
#VU58206 - Absolute Path Traversal
CVE-2021-32803
CWE-36 Medium
No
No
12.22.5-1.el7 17.11.2021 SB2021080329
SB2022031104
SB2022060618
and 26 more
#VU58205 - Absolute Path Traversal
CVE-2021-32804
CWE-36 Medium
No
No
12.22.5-1.el7 17.11.2021 SB2021080328
SB2022031104
SB2022060618
and 27 more
#VU58203 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-37712
CWE-22 Medium
No
No
12.22.12-2.el7 17.11.2021 SB2021111707
SB2021111710
SB2022031104
and 24 more
#VU58202 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-37701
CWE-22 Medium
No
No
12.22.12-2.el7 17.11.2021 SB2021111706
SB2021111710
SB2022031104
and 24 more
#VU57498 - Improper input validation
CVE-2021-22931
CWE-20 High
No
No
12.22.5-1.el7 19.10.2021 SB2021101945
SB2022020113
SB2022031104
and 28 more
#VU56967 - Improper input validation
CVE-2021-3672
CWE-20 Medium
No
No
12.22.5-1.el7 30.09.2021 SB2021093017
SB2021110508
SB2022031104
and 39 more
#VU55560 - Use After Free
CVE-2021-22930
CWE-416 High
No
No
12.22.5-1.el7 03.08.2021 SB2021080320
SB2021080324
SB2021080325
and 35 more
#VU55315 - Incorrect Regular Expression
CVE-2021-23343
CWE-185 Medium
No
No
12.22.5-1.el7 26.07.2021 SB2021072624
SB2021072625
SB2022060618
and 24 more
#VU52985 - Incorrect Regular Expression
CVE-2020-28469
CWE-185 Medium
No
No
12.22.5-1.el7 10.05.2021 SB2021051002
SB2021051004
SB2021072625
and 26 more


Showing elements 1 - 20 out of 43