Lucene search

K
redosRedosROS-20240904-05
HistorySep 04, 2024 - 12:00 a.m.

ROS-20240904-05

2024-09-0400:00:00
redos.red-soft.ru
2
node.js
vulnerability
arbitrary code
execution
unix
access control

CVSS3

6.5

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H

AI Score

7.7

Confidence

Low

Node.js software platform vulnerability is related to improper access control. Exploitation
vulnerability could allow an attacker to execute arbitrary code

OSVersionArchitecturePackageVersionFilename
redos7.3x86_64nodejs< 18.20.4-1UNKNOWN

CVSS3

6.5

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H

AI Score

7.7

Confidence

Low