QID 376730

Date Published: 2022-07-26

QID 376730: Node.js Multiple Vulnerabilities (JULY 2022)

Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside of a web browser.

Affected Versions:
Node.js version 18.X series prior to version 18.5.0
Node.js version 16.X series all versions up to 16.16.0
Node.js version 14.X series all versions up to 14.20.0
QID Detection Logic:(Authenticated)
This QID checks for the vulnerable version of node.js at HKLM\SOFTWARE\Node.js

Successful exploitation could lead attacker to arbitrary code execution

  • CVSS V3 rated as Critical - 9.1 severity.
  • CVSS V2 rated as Critical - 8.5 severity.
  • Solution
    The vendors have released fixed version of Node.js node.js
    Vendor References

    CVEs related to QID 376730

    Software Advisories
    Advisory ID Software Component Link
    july-2022-security-releases URL Logo nodejs.org/en/blog/vulnerability/july-2022-security-releases/