nodejs:12/nodejs-nodemon vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the nodejs:12/nodejs-nodemon package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • M
Resource Exhaustion

<0:2.0.3-1.module_el8.4.0+2521+c668cc9f
  • M
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<0:2.0.3-1.module_el8.4.0+2521+c668cc9f
  • M
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<0:2.0.3-1.module_el8.4.0+2521+c668cc9f
  • M
CVE-2021-27290

<0:2.0.3-1.module_el8.4.0+2521+c668cc9f
  • M
Inefficient Regular Expression Complexity

<0:2.0.3-1.module_el8.4.0+2521+c668cc9f
  • M
Out-of-bounds Read

<0:2.0.3-1.module_el8.4.0+2521+c668cc9f
  • M
HTTP Request Smuggling

<0:2.0.3-1.module_el8.4.0+2521+c668cc9f
  • M
Use After Free

<0:2.0.3-1.module_el8.4.0+2521+c668cc9f
  • M
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<0:2.0.3-1.module_el8.4.0+2521+c668cc9f
  • M
CVE-2020-7754

<0:2.0.3-1.module_el8.4.0+2521+c668cc9f
  • M
Resource Exhaustion

<0:2.0.3-1.module_el8.4.0+2521+c668cc9f
  • M
Arbitrary Argument Injection

<0:2.0.3-1.module_el8.4.0+2521+c668cc9f
  • M
Improper Input Validation

<0:2.0.3-1.module_el8.4.0+2521+c668cc9f
  • H
Cross-site Scripting (XSS)

<0:2.0.3-1.module_el8.4.0+2521+c668cc9f
  • H
Directory Traversal

<0:2.0.3-1.module_el8.4.0+2521+c668cc9f
  • H
Link Following

<0:2.0.3-1.module_el8.4.0+2521+c668cc9f
  • H
CVE-2021-23343

<0:2.0.3-1.module_el8.4.0+2521+c668cc9f
  • H
Use After Free

<0:2.0.3-1.module_el8.4.0+2521+c668cc9f
  • H
Improper Certificate Validation

<0:2.0.3-1.module_el8.4.0+2521+c668cc9f
  • H
Improper Input Validation

<0:2.0.3-1.module_el8.4.0+2521+c668cc9f
  • H
Use After Free

<0:2.0.3-1.module_el8.4.0+2521+c668cc9f
  • H
CVE-2021-22884

<0:2.0.3-1.module_el8.4.0+2521+c668cc9f
  • H
Missing Release of Resource after Effective Lifetime

<0:2.0.3-1.module_el8.4.0+2521+c668cc9f