QID 378951

Date Published: 2023-10-25

QID 378951: Node.js Multiple Security Vulnerabilties (October 13, 2023 Security Release)

Node.js is a platform built on Chrome's JavaScript runtime for easily building fast, scalable network applications.

Multiple security vulnerabilities has been patched in October 13, 2023 node.js release

Affected Products:
Node.js versions from 18.x prior to v18.18.2
Node.js versions from 20.x prior to v20.8.1

QID Detection Logic:(Authenticated)
This QID checks for the vulnerable version of node.js at HKLM\SOFTWARE\Node.js and HKLM\SOFTWARE\WOW6432Node\Node.js

Successful exploitation of these vulnerabilities may affect Confidentiality, Integrity and Availability.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Vendor has released Node.js version v18.18.2 and v20.8.1 to fix this issue. For more details please refer CVE-2023-30586.
    Software Advisories
    Advisory ID Software Component Link
    Node.js Changelog URL Logo nodejs.org/en/blog/vulnerability/october-2023-security-releases