HIGH
Denial of Service (DoS)
Published Mar 16, 2022
7.5
HIGHCVSS 3.1
EPSS 1.32%
Description
The package node-lmdb before 0.9.7 are vulnerable to Denial of Service (DoS) when defining a non-invokable ToString value, which will cause a crash during type check.
Affected products
- Vendor n/a Product Node-Lmdb Defaultn/a
- Version unspecifiedStatusaffectedConstraints<0.9.7
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Node-Lmdb | n/a |
|
- < 0.9.7
No data.
No Red Hat product state for this CVE.
node-lmdb
npm
Introduced 0 Fixed 0.9.7
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | node-lmdb | 0 | 0.9.7 |
Remediation
No remediation recorded yet.
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-1280 Advisory
- https://github.com/Venemo/node-lmdb/commit/97760104c0fd311206b88aecd91fa1f59fe2b85a x_refsource_MISCPatchThird Party Advisory
- https://github.com/advisories/GHSA-32j9-6qqm-mq9g Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-21164
- https://snyk.io/vuln/SNYK-JS-NODELMDB-2400723 x_refsource_MISCExploitPatchThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-1280 | Advisory | |
| https://github.com/Venemo/node-lmdb/commit/97760104c0fd311206b88aecd91fa1f59fe2b85a | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/advisories/GHSA-32j9-6qqm-mq9g | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-21164 | ||
| https://snyk.io/vuln/SNYK-JS-NODELMDB-2400723 | x_refsource_MISCExploitPatchThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner snyk
Published Mar 16, 2022
Updated Sep 16, 2024
Reserved Feb 24, 2022
Link CVE-2022-21164
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2022-1280 GHSA-32J9-6QQM-MQ9G Assigner snyk
Published Mar 16, 2022
Updated Sep 16, 2024
Exploited since n/a
Link EUVD-2022-1280