Information disclosure in Node.js - CVE-2018-7166
Published: August 21, 2018 / Updated: August 22, 2018
Vulnerability details
The vulnerability allows a local attacker to obtain potentially sensitive information.
The vulnerability exists due to the Buffer.alloc() function of the affected software returns uninitialized memory. A local attacker can submit malicious arguments to the Buffer.alloc() function and cause a targeted system to return uncleared memory blocks that hold sensitive information.
Affected software
Red Hat Software Collections
rh-nodejs10-nodejs (Red Hat package)