-
Notifications
You must be signed in to change notification settings - Fork 5
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
libuv CVE-2024-24806 in Node 20.15 #189
Comments
@nodejs/libuv does it affect Node.js? |
We included fixes for CVE-2024-24806 in https://nodejs.org/en/blog/vulnerability/february-2024-security-releases |
@richardlau the version appears to be the same. Was this patch backported to Node v20.15.0? The post claims it was fixed on Node 20.x |
Yes, by nodejs/node#51737 in Node.js 20.11.1. |
Wow! That's great news. Thank you @richardlau I'll bookmark the release and search up CVEs in the future |
There is a critical vulnerbility that was not fixed in the last NodeJS minor version fix. It is coming up on vulnerability scans and creating problems.
https://nvd.nist.gov/vuln/detail/CVE-2024-24806
https://github.com/nodejs/node/blob/v20.15.0/deps/uv/ChangeLog#L1
The text was updated successfully, but these errors were encountered: