-
-
Notifications
You must be signed in to change notification settings - Fork 6
Open
Labels
dont-fall-in-threat-modelWhen a vulnerability might affect Node.js but do not fall in the Node.js threat modelWhen a vulnerability might affect Node.js but do not fall in the Node.js threat model
Description
Hello,
In our recent scans we have detected the following CVEs from V8 though its dependency in node.js:
https://nvd.nist.gov/vuln/detail/CVE-2024-4761
https://nvd.nist.gov/vuln/detail/CVE-2024-4947
https://nvd.nist.gov/vuln/detail/CVE-2024-5274
We would like to know if:
- These CVEs do affect node.js if unpatched,
- If there are plans to port this fixes to the V8 versions in use for node 18 and 20, and/or
- if you would be willing to accept patches for fixing these CVEs in V8 branches used by the node versions mentioned above.
Thank you in advance.
Metadata
Metadata
Assignees
Labels
dont-fall-in-threat-modelWhen a vulnerability might affect Node.js but do not fall in the Node.js threat modelWhen a vulnerability might affect Node.js but do not fall in the Node.js threat model