nodejs / nodejs/nodejs-dependency-vuln-assessments

Whether V8: CVE-2024-4761, CVE-2024-4947 and/or CVE-2024-5274 has impact on the use of nodejs

Open
#191 8 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

dont-fall-in-threat-model
Dominant language
Python
Stars
22
Forks
7
PR merge metrics
No merged PRs in 30d

Description

Hello,

In our recent scans we have detected the following CVEs from V8 though its dependency in node.js:
https://nvd.nist.gov/vuln/detail/CVE-2024-4761
https://nvd.nist.gov/vuln/detail/CVE-2024-4947
https://nvd.nist.gov/vuln/detail/CVE-2024-5274

We would like to know if:

  1. These CVEs do affect node.js if unpatched,
  2. If there are plans to port this fixes to the V8 versions in use for node 18 and 20, and/or
  3. if you would be willing to accept patches for fixing these CVEs in V8 branches used by the node versions mentioned above.

Thank you in advance.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Review the three linked NVD entries and the V8 versions used by Node.js 18 and 20. Determine whether the CVEs affect Node.js and whether fixes or patches are planned or acceptable for those branches; completion would be a documented assessment or maintainer decision.

Written by the indexing model from the issue text.

Assessment

Tech stack
node.js
Domain
security
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.