Lucene search

K
oraclelinuxOracleLinuxELSA-2024-5815
HistoryAug 26, 2024 - 12:00 a.m.

nodejs:20 security update

2024-08-2600:00:00
linux.oracle.com
6
nodejs
security update
cve-2024-36137
cve-2024-22018
cve-2024-22020
nodemon
packaging
unix

CVSS3

6.5

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H

AI Score

7.4

Confidence

Low

EPSS

0

Percentile

16.3%

nodejs
[1:20.16.0-1]

  • Update to 20.16.0
    Fixes: CVE-2024-36137 CVE-2024-22018 CVE-2024-22020
    nodejs-nodemon
    nodejs-packaging

CVSS3

6.5

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H

AI Score

7.4

Confidence

Low

EPSS

0

Percentile

16.3%