QID 996076
Date Published: 2023-11-28
QID 996076: NodeJs (Npm) Security Update for openssl (GHSA-75w2-qv55-x7fv)
The openssl (aka node-openssl) NPM package through 2.0.0 was characterized as "a nonsense wrapper with no real purpose" by its author, and accepts an opts argument that contains a verb field (used for command execution). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-75w2-qv55-x7fv for updates and patch information.
Vendor References
- GHSA-75w2-qv55-x7fv -
github.com/advisories/GHSA-75w2-qv55-x7fv
CVEs related to QID 996076
Software Advisories
| Advisory ID | Software | Component | Link |
|---|