Cyber Resilience
← All news

[UPDATE] [hoch] Node.js: Mehrere Schwachstellen

Our takeCERT-Bund updated its advisory on multiple high-severity flaws in Node.js that let attackers bypass security measures, manipulate data, leak information or cause denial of service. Update if you run it yourself.
Sources (3)
What this means for you — Security leader:CERT-Bund updated its advisory on multiple high-severity flaws in Node.js that let attackers bypass security controls, tamper with data, leak information or cause DoS. Update to a fixed version if you run Node.js.
What this means for you — Lean IT orgs:Node.js has several confirmed vulnerabilities. Update it if you run Node.js yourself.
What this means for you — MSP:Node.js has multiple confirmed high-severity flaws (bypass, tampering, info disclosure, DoS). Check client inventories for self-hosted Node.js instances and ensure they are updated; most hosted or cloud-native stacks are unaffected.
What this means for you — Researcher:CERT-Bund updated its advisory on multiple high-severity flaws in Node.js that let attackers bypass security controls, tamper with data, leak information or cause DoS. Update to a fixed version if you run Node.js.