Joyent Node.js是美国Joyent公司的一套建立在Google V8 JavaScript引擎之上的网络应用平台。inspector是其中的一个调试工具。 Joyent Node.js 6.x及之后版本中的inspector存在安全漏洞。远程攻击者可借助恶意的网站利用该漏洞绕过同源协议检查并通过HTTP协议连接到本地主机或本地网络上的主机,并且可能执行代码。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| The Node.js Project | Node.js | ^6.0.0 || ^8.0.0 || ^9.0.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| The Node.js Project | Node.js | ^6.0.0 || ^8.0.0 || ^9.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2018-7158 | Joyent Node.js path模块输入验证错误漏洞 | |
| CVE-2018-7159 | Joyent Node.js HTTP解析器输入验证错误漏洞 |
No comments yet