vulnerability

FreeBSD: VID-77a6f1c9-d7d2-11ee-bb12-001b217b3468 (CVE-2024-22019): NodeJS -- Vulnerabilities

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
Published
Mar 1, 2024
Added
Mar 2, 2024
Modified
Dec 10, 2025

Description

Node.js reports: Code injection and privilege escalation through Linux capabilities- (High) http: Reading unprocessed HTTP request with unbounded chunk extension allows DoS attacks- (High) Path traversal by monkey-patching Buffer internals- (High) setuid() does not drop all privileges due to io_uring - (High) Node.js is vulnerable to the Marvin Attack (timing variant of the Bleichenbacher attack against PKCS#1 v1.5 padding) - (Medium) Multiple permission model bypasses due to improper path traversal sequence sanitization - (Medium) Improper handling of wildcards in --allow-fs-read and --allow-fs-write (Medium) Denial of Service by resource exhaustion in fetch() brotli decoding - (Medium)

Solutions

freebsd-upgrade-package-nodefreebsd-upgrade-package-node16freebsd-upgrade-package-node18freebsd-upgrade-package-node20freebsd-upgrade-package-node21
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.