Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

CVE-2022-38900 (npm/decode-uri-component) found on v14.x dependancy #98

Closed
siemenstan opened this issue Dec 21, 2022 · 5 comments
Closed
Labels

Comments

@siemenstan
Copy link

@RafaelGSS
This public CVE is reported against decode-uri-component, which is a dependency of the npm in NodeJs 14.x.
Vulnerability ID: CVE-2022-38900
Vulnerability URL: https://nvd.nist.gov/vuln/detail/CVE-2022-38900

found in node-v14.21.2-linux-x64-musl.tar.xz (lib\node_modules\npm\node_modules\decode-uri-component)
src: node/deps/npm/node_modules/decode-uri-component/

@mhdawson
Copy link
Member

@siemenstan do you know how/if it affects npm as that will depend on what APIs are used from decode-uri-component right?

@mhdawson mhdawson changed the title CVE-2022-38900 (decode-uri-component) found on v14.x dependancy CVE-2022-38900 (npm/decode-uri-component) found on v14.x dependancy Dec 21, 2022
@mhdawson mhdawson added the v14.x label Dec 21, 2022
@siemenstan
Copy link
Author

siemenstan commented Dec 22, 2022

@mhdawson No, my app doesn't use the decode-uri-component. It's just my company security scan system is picking up this public CVE from my app container image with the node 14.x image.

Btw, following the CVE-2022-3517 issue, it has been addressed in pr#45936

@RafaelGSS
Copy link
Member

@nodejs/npm could you check if that affect Node.js itself?

@wraithgar
Copy link

nodejs/node#45936 addresses this

@mhdawson
Copy link
Member

Believe this was addressed by recent security release, closing

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
Projects
None yet
Development

No branches or pull requests

4 participants