QID 375828

Date Published: 2021-09-07

QID 375828: Node.js Multiple Vulnerabilities (August 2021)

Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside of a web browser.

Affected Versions:
Node.js version 12.X series prior to version Node.js v12.22.6 (LTS)
Node.js version 14.X series prior to version Node.js v14.17.6 (LTS)
QID Detection Logic:(Authenticated)
This QID checks for the vulnerable version of node.js at HKLM\SOFTWARE\Node.js and HKLM\SOFTWARE\WOW6432Node\Node.js

Attacker could compromise Confidentiality, Integrity and Availability

  • CVSS V3 rated as Critical - 8.6 severity.
  • CVSS V2 rated as Medium - 5.8 severity.
  • Solution
    The vendors have released fixed version of Node.js node.js
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    aug-2021-security-releases2 URL Logo nodejs.org/en/blog/vulnerability/aug-2021-security-releases2/