nodejs:14/nodejs-nodemon vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the nodejs:14/nodejs-nodemon package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • M
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<0:2.0.15-1.module_el8.6.0+2904+f21ad6f4
  • M
Directory Traversal

<0:2.0.15-1.module_el8.6.0+2904+f21ad6f4
  • M
Directory Traversal

<0:2.0.15-1.module_el8.6.0+2904+f21ad6f4
  • M
HTTP Request Smuggling

<0:2.0.15-1.module_el8.6.0+2904+f21ad6f4
  • M
HTTP Request Smuggling

<0:2.0.15-1.module_el8.6.0+2904+f21ad6f4
  • M
Inefficient Regular Expression Complexity

<0:2.0.15-1.module_el8.6.0+2904+f21ad6f4
  • M
Inefficient Regular Expression Complexity

<0:2.0.15-1.module_el8.6.0+2904+f21ad6f4
  • M
Resource Exhaustion

<0:2.0.15-1.module_el8.6.0+2904+f21ad6f4
  • M
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<0:2.0.20-2.module_el8.7.0+3373+a4c18c43
  • M
Information Exposure

<0:2.0.20-2.module_el8.7.0+3373+a4c18c43
  • M
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<0:2.0.20-2.module_el8.7.0+3373+a4c18c43
  • M
HTTP Request Smuggling

<0:2.0.19-2.module_el8.6.0+3261+490666b3
  • M
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<0:2.0.19-2.module_el8.6.0+3261+490666b3
  • M
Improper Certificate Validation

<0:2.0.19-2.module_el8.6.0+3261+490666b3
  • M
Improper Certificate Validation

<0:2.0.19-2.module_el8.6.0+3261+490666b3
  • M
Improper Certificate Validation

<0:2.0.19-2.module_el8.6.0+3261+490666b3
  • M
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<0:2.0.15-1.module_el8.6.0+2904+f21ad6f4
  • H
Improper Input Validation

<0:2.0.20-3.module_el8.7.0+3551+53700ee8
  • H
Cross-site Scripting (XSS)

<0:2.0.3-1.module_el8.4.0+2521+c668cc9f
  • H
Directory Traversal

<0:2.0.3-1.module_el8.4.0+2521+c668cc9f
  • H
Link Following

<0:2.0.3-1.module_el8.4.0+2521+c668cc9f
  • H
CVE-2021-23343

<0:2.0.3-1.module_el8.4.0+2521+c668cc9f
  • H
Use After Free

<0:2.0.3-1.module_el8.4.0+2521+c668cc9f
  • H
Improper Certificate Validation

<0:2.0.3-1.module_el8.4.0+2521+c668cc9f
  • H
Improper Input Validation

<0:2.0.3-1.module_el8.4.0+2521+c668cc9f
  • H
Use After Free

<0:2.0.3-1.module_el8.4.0+2521+c668cc9f
  • M
CVE-2022-33987

<0:2.0.19-2.module_el8.6.0+3261+490666b3
  • M
HTTP Request Smuggling

<0:2.0.19-2.module_el8.6.0+3261+490666b3
  • M
HTTP Request Smuggling

<0:2.0.19-2.module_el8.6.0+3261+490666b3
  • M
HTTP Request Smuggling

<0:2.0.19-2.module_el8.6.0+3261+490666b3
  • M
OS Command Injection

<0:2.0.19-2.module_el8.6.0+3261+490666b3
  • M
OS Command Injection

<0:2.0.20-2.module_el8.7.0+3373+a4c18c43
  • M
Inefficient Regular Expression Complexity

<0:2.0.20-2.module_el8.7.0+3373+a4c18c43
  • H
Untrusted Search Path

<0:2.0.20-3.module_el8.7.0+3551+53700ee8
  • H
Incorrect Authorization

<0:2.0.20-3.module_el8.7.0+3551+53700ee8
  • H
Improper Validation of Specified Quantity in Input

<0:2.0.20-3.module_el8.7.0+3551+53700ee8
  • H
Inefficient Regular Expression Complexity

<0:2.0.20-3.module_el8.7.0+3551+53700ee8
  • H
Inefficient Regular Expression Complexity

<0:2.0.20-3.module_el8.7.0+3551+53700ee8