Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Consultation on CVE-2018-25032 #4045

Closed
wangmomo1126 opened this issue Dec 7, 2022 · 1 comment
Closed

Consultation on CVE-2018-25032 #4045

wangmomo1126 opened this issue Dec 7, 2022 · 1 comment

Comments

@wangmomo1126
Copy link

Details

The zlib version bundled with the latest available Node.js may be affected by CVE-2018-25032, a high-severity security vulnerability that's being re-analyzed by NVD. However, there's a more recent version of zlib that is unaffected by said vulnerability (version 1.2.12).
Our project uses Node.js as a third-party component and this vulnerability was detected by one of our security scanners and we want to make the Node.js community aware of this situation.I want to know if nodejs version 14.x is affected by this vulnerability

Node.js version

14.21.1

Example code

No response

Operating system

linux

Scope

Open Source Vulnerabilities

Module and version

zlib

@bmuenzenmeyer
Copy link
Contributor

closing this per the resolution mentioned within nodejs/security-wg#792

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants