VDB
WID-SEC-W-2025-0156
WID-SEC-W-2025-0156
PUBLISHED
Ein Angreifer kann mehrere Schwachstellen in Node.js ausnutzen, um Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen preiszugeben, einen Denial-of-Service-Zustand herbeizuführen oder nicht näher spezifizierte Angriffe zu starten.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Open Source Node.js v21.x | ||
| Open Source Node.js v18.20.6 | ||
| Red Hat Enterprise Linux | ||
| Fedora Linux | ||
| Open Source Node.js v19.x | ||
| Gentoo Linux | ||
| Oracle Linux | ||
| Debian Linux | ||
| Open Source Node.js v17.x | ||
| IBM App Connect Enterprise | ||
| V24.0.0 | ||
| Open Source Node.js <v23.6.1 | ||
| Open Source Node.js v23.6.1 | ||
| Open Source Node.js <v20.18.2 | ||
| RESF Rocky Linux | ||
| Red Hat Enterprise Linux Developer Hub 1 | ||
| Open Source Node.js v20.18.2 | ||
| Open Source Node.js <v22.13.1 | ||
| Open Source Node.js <v18.20.6 | ||
| Open Source Node.js v22.13.1 |
Timeline
- Jan 21, 2025 CVE Published
- Jun 12, 2025 CVE Updated
- Apr 1, 2026 Distribution Patch
- Apr 1, 2026 Distribution Patch
- Apr 1, 2026 Distribution Patch
- Apr 1, 2026 Distribution Patch
- Apr 1, 2026 Distribution Patch
- Apr 1, 2026 Distribution Patch
- Apr 1, 2026 Distribution Patch
- Apr 1, 2026 Distribution Patch
References
- https://linux.oracle.com/errata/ELSA-2025-7433.html url
- https://bodhi.fedoraproject.org/updates/FEDORA-2025-8e0ecb9bb6 url
- https://bodhi.fedoraproject.org/updates/FEDORA-2025-e330d34ecc url
- https://bodhi.fedoraproject.org/updates/FEDORA-2025-cc8f9d8943 url
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/WLMBUS6KTOM5ZRBZUFNAWPANSHPLYG3W/ url
- https://access.redhat.com/errata/RHSA-2025:1351 url
- https://linux.oracle.com/errata/ELSA-2025-1351.html url
- https://errata.build.resf.org/RLSA-2025:1446 url
- https://access.redhat.com/errata/RHSA-2025:1611 url
- https://access.redhat.com/errata/RHSA-2025:1613 url
- https://linux.oracle.com/errata/ELSA-2025-1582.html url
- https://linux.oracle.com/errata/ELSA-2025-1611.html url
- https://errata.build.resf.org/RLSA-2025:1582 url
- https://www.ibm.com/support/pages/node/7185575 url
- https://security.business.xerox.com/wp-content/uploads/2025/06/Xerox-Security-Bulletin-XRX25-012-for-Xerox-FreeFlow-Print-Server-v9.pdf url
- https://security.gentoo.org/glsa/202506-08 url
- https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-0156.json advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2025-87a8af2834 url
- https://bodhi.fedoraproject.org/updates/FEDORA-2025-54958ff9e2 url
- https://bodhi.fedoraproject.org/updates/FEDORA-2025-76fc32d433 url
…and 21 more