VDB
BDU%3A2024-11495
BDU%3A2024-11495
PUBLISHED
CVSS 7.800000190734863 HIGH
Уязвимость пакета cross-spawn программной платформы Node.js, позволяющая нарушителю вызвать отказ в обслуживании
Risk Scores
CVSS 2.0
7.800000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Novell Inc., Red Hat Inc., NPM, Inc., АО «Экзософт», Node.js Foundation | openSUSE Tumbleweed, Red Hat OpenShift Container Platform, Red Hat Advanced Cluster Security, Suse Linux Enterprise Server, SUSE Linux Enterprise Server for SAP Applications, SUSE Linux Enterprise High Performance Computing, OpenSUSE Leap, Openshift Service Mesh, SUSE Linux Enterprise Module for Web Scripting, cross-spawn, VMmanager 6 (запись в едином реестре российских программ №9662), Node.js |
Timeline
- Dec 25, 2024 CVE Published
- Feb 10, 2026 CVE Updated
References
- https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-8366349 url
- https://security.snyk.io/vuln/SNYK-JS-CROSSSPAWN-8303230 url
- https://github.com/moxystudio/node-cross-spawn/commit/5ff3a07d9add449021d806e45c4168203aa833ff url
- https://github.com/moxystudio/node-cross-spawn/commit/640d391fde65388548601d95abedccc12943374f url
- https://www.suse.com/security/cve/CVE-2024-21538.html url
- https://access.redhat.com/security/cve/cve-2024-21538 url
- https://github.com/moxystudio/node-cross-spawn/pull/160 advisory
- https://lk.astra.ru/ advisory
- https://wiki.astralinux.ru/x/ziLoD advisory