[FREEBSD:F53DAB71-1B15-11EC-9D9D-0022489AD614] Node.js -- July 2021 Security Releases (2)

Severity Critical
Affected Packages 2
CVEs 1

Node.js reports:

  Use after free on close http2 on stream canceling (High) (CVE-2021-22930)
  Node.js is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption, to change process behavior.
Package Affected Version
pkg:freebsd/node14 < 14.17.4
pkg:freebsd/node < 16.6.0
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:freebsd/node14 node14 < 14.17.4
Affected pkg:freebsd/node node < 16.6.0
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...