QID 375692

Date Published: 2021-07-08

QID 375692: Node.js Denial Of Service and PATH,DLL hijacking Vulnerabilities July 2021

Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside of a web browser.

Affected Versions:
All versions of the 12.x release line before 12.22.2
Versions of the 14.x release line before 14.17.2

QID Detection Logic:(Authenticated)
This QID checks for the vulnerable version of node.js at HKLM\SOFTWARE\Node.js and HKLM\SOFTWARE\WOW6432Node\Node.js

Successful exploitation can lead to Denial of Service and PATH, and DLL hijacking escalation attacks.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    The vendors have released fixed in 12.22.2 and 14.17.2 version of Node.js node.js
    Vendor References

    CVEs related to QID 375692

    Software Advisories
    Advisory ID Software Component Link
    july-2021-security-releases URL Logo nodejs.org/en/blog/vulnerability/july-2021-security-releases/