RHSA-2022:6449
Advisory lineage Upstream: 6 Downstream: 0
Published: 22 Oct 2024, 00:30
Last modified:01 May 2026, 10:02
Vulnerability Summary
Overall Risk (default)
medium
30/100 CVSS Score
7.5 HIGH
3.1 (osv_red_hat)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
22 Oct 2024, 00:30
Published
Vulnerability first disclosed
01 May 2026, 10:02
Last Modified
Vulnerability information updated
Description
Red Hat Security Advisory: nodejs:16 security and bug fix update
CVSS Metrics
- v3.1•HIGH•Score: 7.5CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Systems
- redhat•nodejs
< 1:16.16.0-3.module+el8.6.0+16248+76b0e185
- redhat•nodejs-debuginfo
< 1:16.16.0-3.module+el8.6.0+16248+76b0e185
- redhat•nodejs-debugsource
< 1:16.16.0-3.module+el8.6.0+16248+76b0e185
- redhat•nodejs-devel
< 1:16.16.0-3.module+el8.6.0+16248+76b0e185
- redhat•nodejs-docs
< 1:16.16.0-3.module+el8.6.0+16248+76b0e185
- redhat•nodejs-full-i18n
< 1:16.16.0-3.module+el8.6.0+16248+76b0e185
- redhat•nodejs-nodemon
< 0:2.0.19-2.module+el8.6.0+16240+7ca51420
- redhat•nodejs-packaging
< 0:25-1.module+el8.5.0+10992+fac5fe06
- redhat•npm
< 1:8.11.0-1.16.16.0.3.module+el8.6.0+16248+76b0e185
References (32)
- https://access.redhat.com/errata/RHSA-2022:6449
- https://access.redhat.com/security/updates/classification/#moderate
- https://bugzilla.redhat.com/show_bug.cgi?id=2007557
- https://bugzilla.redhat.com/show_bug.cgi?id=2102001
- https://bugzilla.redhat.com/show_bug.cgi?id=2105422
- https://bugzilla.redhat.com/show_bug.cgi?id=2105426
- https://bugzilla.redhat.com/show_bug.cgi?id=2105428
- https://bugzilla.redhat.com/show_bug.cgi?id=2105430
- https://bugzilla.redhat.com/show_bug.cgi?id=2106369
- https://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_6449.json
- https://access.redhat.com/security/cve/CVE-2021-3807
- https://www.cve.org/CVERecord?id=CVE-2021-3807
- https://nvd.nist.gov/vuln/detail/CVE-2021-3807
- https://huntr.dev/bounties/5b3cf33b-ede0-4398-9974-800876dfd994
- https://access.redhat.com/security/cve/CVE-2022-32212
- https://www.cve.org/CVERecord?id=CVE-2022-32212
- https://nvd.nist.gov/vuln/detail/CVE-2022-32212
- https://nodejs.org/en/blog/vulnerability/july-2022-security-releases/
- https://access.redhat.com/security/cve/CVE-2022-32213
- https://www.cve.org/CVERecord?id=CVE-2022-32213
- https://nvd.nist.gov/vuln/detail/CVE-2022-32213
- https://access.redhat.com/security/cve/CVE-2022-32214
- https://www.cve.org/CVERecord?id=CVE-2022-32214
- https://nvd.nist.gov/vuln/detail/CVE-2022-32214
- https://access.redhat.com/security/cve/CVE-2022-32215
- https://www.cve.org/CVERecord?id=CVE-2022-32215
- https://nvd.nist.gov/vuln/detail/CVE-2022-32215
- https://access.redhat.com/security/cve/CVE-2022-33987
- https://www.cve.org/CVERecord?id=CVE-2022-33987
- https://nvd.nist.gov/vuln/detail/CVE-2022-33987
- https://github.com/sindresorhus/got/pull/2047
- https://github.com/sindresorhus/got/releases/tag/v11.8.5